Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

better-auth — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting better-auth. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Better-auth is an authentication and authorization library designed to secure web applications with customizable authentication flows. Historically, it has been susceptible to remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities, primarily due to improper input validation and misconfigurations. The library's security posture has been impacted by five disclosed CVEs, highlighting risks in session management and OAuth implementations. While better-auth offers flexible security features, its complex configuration options have led to misdeployments in production environments. Users must carefully implement security controls to mitigate potential exploitation paths, particularly in multi-tenant deployments where isolation between user contexts is critical.

Top products by better-auth: better-auth better-icons
High2026-07-16
fix(organization): default-on `requireEmailVerificationOnInvitation` … · better-auth/better-auth@23094a6 · GitHub
Medium2026-07-16
fix(organization): default-on `requireEmailVerificationOnInvitation` & extend gate to get/list by gustavovalverde · Pull
HighCVE-2026-535142026-07-16
Unauthorized invitation acceptance via unverified email match in organization plugin · Advisory · better-auth/better-aut
High2026-07-16
fix(sso): require org admin role to register SSO providers by stewartjarod · Pull Request #9220 · better-auth/better-aut
High2026-07-16
Release v1.6.11 · better-auth/better-auth · GitHub
HighCVE-2026-535152026-07-16
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role · Advisory · bett
High2026-07-16
fix(sso): require org admin role to register SSO providers (#9220) · better-auth/better-auth@86765f1 · GitHub
Unknown2026-07-16
Merge commit from fork · better-auth/better-auth@c6918ec · GitHub
High2026-07-16
fix(device-authorization): bind approval to verifier session (#9573) · better-auth/better-auth@99a254a · GitHub
High2026-07-16
fix(device-authorization): bind approval to verifier session by gustavovalverde · Pull Request #9573 · better-auth/bette
HighCVE-2026-555172026-07-16
@better-auth/oauth-provider: OAuth refresh-token rotation forks the token family on concurrent redemption · Advisory · b
High2026-07-16
device-authoriziation: session hijack via missing owner binding on approve and deny · Advisory · better-auth/better-auth
High2026-07-16
Merge commit from fork · better-auth/better-auth@b4bc65a · GitHub
HighCVE-2026-505182026-07-16
@better-auth/oauth-provider: OAuth authorization-code grant allows concurrent redemption when two token requests race th
High2026-07-16
fix(oidc-provider, mcp): authenticate confidential clients on refresh_token grant by gustavovalverde · Pull Request #957
UnknownCVE-2024-535122026-07-16
OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins · Advisory · better-auth/b
High2026-07-16
@better-auth/sso: Server-side request forgery via unvalidated OIDC endpoints on provider registration · Advisory · bette
High2026-07-16
fix(sso): validate user-supplied OIDC endpoint URLs at registration and update by gustavovalverde · Pull Request #9574 ·
High2026-07-16
fix(oauth): block OAuth linking to unverified local accounts by gustavovalverde · Pull Request #9578 · better-auth/bette
HighCVE-2026-355162026-07-16
core: pre-account hijacking via OAuth implicit linking (nOAuth-class) · Advisory · better-auth/better-auth · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with better-auth. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.