better-auth是better-auth团队开源的一个身份验证框架。 better-auth 1.6.11之前版本存在资源管理错误漏洞,该漏洞源于在配置secondaryStorage且storeSessionInDatabase为false时,通过admin、anonymous或SCIM端点删除用户时未能删除缓存的会话,可能导致攻击者重用已删除用户的会话令牌,在账户删除后长达七天内维持身份验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| better-auth | better-auth | 0.3.4< 1.6.11 |
affected |
1.6.11 |
unaffected | ||
1.6.0< 1.6.11 |
affected | ||
1.6.11 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| better-auth | better-auth | 0.3.4 ~ 1.6.11 | - |
|
| better-auth | better-auth | 1.6.0 ~ 1.6.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67330 | 9.9 CRITICAL | better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collision |
| CVE-2026-67336 | 8.7 HIGH | better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider |
| CVE-2026-67327 | 8.3 HIGH | better-auth before 1.6.22 Account Takeover via Magic-Link Email-OTP |
| CVE-2026-67331 | 8.3 HIGH | better-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization Bypass |
| CVE-2026-67328 | 8.1 HIGH | @better-auth/sso before 1.6.21 Account Takeover via SSO |
| CVE-2026-67333 | 7.2 HIGH | better-auth before 1.6.13 Stored XSS via javascript redirect_uri |
| CVE-2026-67329 | 7.1 HIGH | @better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscription |
| CVE-2025-71403 | 7.1 HIGH | better-auth before 1.1.20 Open Redirect via trustedOrigins Bypass |
| CVE-2026-67337 | 6.5 MEDIUM | better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieCache |
| CVE-2026-67332 | 6.4 MEDIUM | @better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypass |
| CVE-2026-67335 | 5.3 MEDIUM | better-auth before 1.6.2 OAuth State Validation Bypass |
| CVE-2025-71404 | 5.1 MEDIUM | better-auth before 1.1.16 Reflected XSS via error parameter |
| CVE-2025-71402 | 2.0 LOW | better-auth before 1.4.0 Session Revocation via Forged Cookie |
No comments yet