Search
Search Results (6 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-67337 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-01 | 6.5 Medium |
| better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching. | ||||
| CVE-2026-67335 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-01 | 5.3 Medium |
| better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles. | ||||
| CVE-2025-71404 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-01 | N/A |
| better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute arbitrary JavaScript in the context of the user's browser. The issue is fixed in version 1.1.16. | ||||
| CVE-2026-67334 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-01 | 3.8 Low |
| better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion. | ||||
| CVE-2026-67333 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-01 | 7.2 High |
| better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the authorization server later returns unchanged in the consent response. If the deployment's consent page navigates the browser to the returned redirectURI (e.g. assigning it to window.location.href), the attacker's JavaScript executes in the authorization-server origin, exposing the victim's session and enabling account takeover. | ||||
| CVE-2025-71403 | 1 Better-auth | 2 Better-auth\/oauth-provider, Better Auth | 2026-08-01 | 7.1 High |
| better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover. | ||||
Page 1 of 1.