better-auth oidc-provider stored XSS via malicious redirect_uri
Security Advisory
GHSA-2f93-g445-6523
High
better-auth
Affected:
- better-auth < 1.6.13
- better-auth >= 1.7.0-beta.0, < 1.7.0-beta.4
Fixed in:
- better-auth 1.6.13
- better-auth 1.7.0-beta.4
Referenced CVEs:
CVE-2026-67333 · 7.2
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.