Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
better-auth before 1.6.13 Stored XSS via javascript redirect_uri
Vulnerability Description
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the authorization server later returns unchanged in the consent response. If the deployment's consent page navigates the browser to the returned redirectURI (e.g. assigning it to window.location.href), the attacker's JavaScript executes in the authorization-server origin, exposing the victim's session and enabling account takeover.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
better-auth 跨站脚本漏洞
Vulnerability Description
better-auth是better-auth团队开源的一个身份验证框架。 better-auth 1.6.13之前版本存在跨站脚本漏洞,该漏洞源于通过已弃用的oidc-provider插件和mcp插件注册的redirect_uris缺少scheme验证,可能导致攻击者注册包含javascript:的redirect_uri,在授权服务器源中执行恶意JavaScript,从而暴露用户会话并导致账户接管。
CVSS Information
N/A
Vulnerability Type
N/A