better-auth has 15 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 15. The median CVSS is 8.1 (high), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-345 (5) and CWE-287 (4). Most affected products: better-auth (7), @better-auth/oauth-provider (3), @better-auth/scim (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 15 prev 0
Products
- better-auth 7
- @better-auth/oauth-provider 3
- @better-auth/scim 2
- @better-auth/sso 2
- @better-auth/stripe 1
Worst active — by depth score
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision54CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints53CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins50GHSA-9h47-pqcx-hjr4High· 8.7Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default48GHSA-qq9h-g4jm-xgf3High· 8.3Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in46
better-auth vulnerabilities
CVEs affecting better-auth, newest first. Open any entry for full detail, references, and exploit status.
15 CVEsRSS
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-h3rm-78g3-j7cpHigh· 7.1@better-auth/stripe: cross-organization billing tampering in organization subscription actions
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-qq9h-g4jm-xgf3High· 8.3Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
CVE-2026-53515High· 7.1@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
GHSA-p2fr-6hmx-4528Medium· 6.4@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
CVE-2026-53514High· 7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-53516High· 8.3Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-86j7-9j95-vpqjHigh· 7.7Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-9h47-pqcx-hjr4High· 8.7Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-53518High· 8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-2vg6-77g8-24mpLow· 3.8Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-j8v8-g9cx-5qf4High· 8.3@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
CVE-2026-53512Critical· 9.1Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins