Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

better-auth — Vulnerabilities & Security Advisories 32

Browse all 32 CVE security advisories affecting better-auth. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Better-auth is an authentication and authorization library designed to secure web applications with customizable authentication flows. Historically, it has been susceptible to remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities, primarily due to improper input validation and misconfigurations. The library's security posture has been impacted by five disclosed CVEs, highlighting risks in session management and OAuth implementations. While better-auth offers flexible security features, its complex configuration options have led to misdeployments in production environments. Users must carefully implement security controls to mitigate potential exploitation paths, particularly in multi-tenant deployments where isolation between user contexts is critical.

Found 1 results / 32Clear Filters
High2026-08-02
Double-Slash Path Normalization in rou3 Can Bypass Better Auth disabledPaths config and Rate Limits · Advisory · better-
High2026-08-01
Account takeover via pre-account hijacking on magic-link and email-OTP sign-in · Advisory · better-auth/better-auth · Gi
High2026-08-01
Insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default · Advisory · bet
High2026-08-01
@better-auth/stripe: cross-organization billing tampering in organization subscription actions · Advisory · better-auth/
Critical2026-08-01
@better-auth/sso: account takeover via multiple SSO flaws · Advisory · better-auth/better-auth · GitHub
Critical2026-08-01
@better-auth/scim: account takeover and stale access via SCIM provider-id collision · Advisory · better-auth/better-auth
HighGHSA-2f93-g445-65232026-08-01
oidc-provider(deperecated): stored XSS in the auth-server origin via a javascript: redirect_uri in · Advisory · better-a
High2026-08-01
@better-auth/oauth-provider: access-token audience (resource) not bound to the authorization grant (RFC 8707) · Advisory
Medium2026-08-01
@better-auth/scim: stale sessions persist after user deletion across admin, anonymous, and SCIM flows · Advisory · bette
High2026-08-01
@better-auth/scim: on single tenant use cases authenticated user can regenerate SCIM provider token · Advisory · better-
High2026-08-01
OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE · Advisory · better-auth
High2026-07-16
fix(organization): default-on `requireEmailVerificationOnInvitation` … · better-auth/better-auth@23094a6 · GitHub
Medium2026-07-16
fix(organization): default-on `requireEmailVerificationOnInvitation` & extend gate to get/list by gustavovalverde · Pull
HighCVE-2026-535142026-07-16
Unauthorized invitation acceptance via unverified email match in organization plugin · Advisory · better-auth/better-aut
High2026-07-16
fix(sso): require org admin role to register SSO providers by stewartjarod · Pull Request #9220 · better-auth/better-aut
High2026-07-16
Release v1.6.11 · better-auth/better-auth · GitHub
High2026-07-16
fix(sso): require org admin role to register SSO providers (#9220) · better-auth/better-auth@86765f1 · GitHub
HighCVE-2026-535152026-07-16
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role · Advisory · bett
Unknown2026-07-16
Merge commit from fork · better-auth/better-auth@c6918ec · GitHub
High2026-07-16
fix(device-authorization): bind approval to verifier session by gustavovalverde · Pull Request #9573 · better-auth/bette

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with better-auth. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.