VulnSea

better-auth has 15 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 15. The median CVSS is 8.1 (high), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-345 (5) and CWE-287 (4). Most affected products: better-auth (7), @better-auth/oauth-provider (3), @better-auth/scim (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
15 prev 0

Products

  • better-auth 7
  • @better-auth/oauth-provider 3
  • @better-auth/scim 2
  • @better-auth/sso 2
  • @better-auth/stripe 1
15
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

better-auth vulnerabilities

CVEs affecting better-auth, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

GHSA-rjg6-39jm-rgg4Critical· 9.9
1mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

Midnightbetter-auth · @better-auth/scimvia GHSA
GHSA-h3rm-78g3-j7cpHigh· 7.1
1mo ago

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

Twilightbetter-auth · @better-auth/stripevia GHSA
GHSA-qq9h-g4jm-xgf3High· 8.3
1mo ago

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Twilightbetter-auth · better-authvia GHSA
CVE-2026-53515High· 7.1
2mo ago

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
GHSA-p2fr-6hmx-4528Medium· 6.4
2mo ago

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

Sunlitbetter-auth · @better-auth/oauth-providervia GHSA
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53516High· 8.3
2mo ago

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Twilightbetter-auth · better-authEPSS 0.29%via GHSA
GHSA-86j7-9j95-vpqjHigh· 7.7
2mo ago

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

Twilightbetter-auth · better-authvia GHSA
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Twilightbetter-auth · better-authvia GHSA
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
GHSA-2vg6-77g8-24mpLow· 3.8
2mo ago

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Sunlitbetter-auth · better-authvia GHSA
GHSA-j8v8-g9cx-5qf4High· 8.3
2mo ago

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

Twilightbetter-auth · @better-auth/scimvia GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Midnightbetter-auth · better-authEPSS 0.27%via GHSA
better-auth vulnerabilities (CVEs) · VulnSea