VulnSea

better-auth vulnerabilities

CVEs whose affected-version data names the better-auth package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

GHSA-qq9h-g4jm-xgf3High· 8.3
1mo ago

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Twilightbetter-auth · better-authvia GHSA
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53516High· 8.3
2mo ago

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Twilightbetter-auth · better-authEPSS 0.29%via GHSA
GHSA-86j7-9j95-vpqjHigh· 7.7
2mo ago

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Twilightbetter-auth · better-authvia GHSA
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Twilightbetter-auth · better-authvia GHSA
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
GHSA-2vg6-77g8-24mpLow· 3.8
2mo ago

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Sunlitbetter-auth · better-authvia GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Midnightbetter-auth · better-authEPSS 0.27%via GHSA
better-auth vulnerabilities (CVEs) · VulnSea