better-auth
npm11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting better-authpage 1 of 1
- CVE-2024-56734MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.1.62024-12-30
Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to ma…
- CVE-2025-27143MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.1.202025-02-24
Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of the callbackURL parameter in the email verification endpoin…
- CVE-2025-53535LOWCVSS 2.1EG 2.1✓ Fixed in 1.2.102025-07-07
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/call…
- CVE-2025-61928CRITICALCVSS 9.3EG 9.3✓ Fixed in 1.3.262025-10-09
Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api…
- CVE-2026-45337HIGHCVSS 7.6EG 7.6✓ Fixed in 1.6.112026-06-04
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim …
- CVE-2026-45364HIGHCVSS 7.3EG 7.3✓ Fixed in 1.5.0-beta.92026-05-15
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it received in x-forwarded-for (or the configur…
- CVE-2026-53512CRITICALCVSS 9.1EG 9.1✓ Fixed in 1.6.112026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshTo…
- CVE-2026-53514HIGHCVSS 7.7EG 7.7✓ Fixed in 1.6.112026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabl…
- CVE-2026-53516HIGHCVSS 8.3EG 8.3✓ Fixed in 1.6.112026-07-07
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified:…
- CVE-2026-53517HIGHCVSS 8.1EG 8.1✓ Fixed in 1.6.02026-07-07
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke,…
- CVE-2026-53518HIGHCVSS 8.1EG 7.6✓ Fixed in 1.6.112026-07-07
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code throug…
Check whether better-auth is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for better-auth CVEs against the assets you own.
Start Free Scan →