CVEs we hold for Better-auth
Records whose assigning authority named Better-auth as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-67337better-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieCachebetter-auth
CVE-2026-67332@better-auth/oauth-provider before 1.7.0-beta.4 Authorization Bypassbetter-auth oauth-provider
CVE-2026-67330better-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID Collisionbetter-auth scim
CVE-2026-67329@better-auth/stripe before 1.6.21 Authorization Bypass via Organization Subscriptionbetter-auth stripe
CVE-2026-53518Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemptionbetter-auth
CVE-2026-53517Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forkingbetter-auth; @better-auth oauth-provider
CVE-2026-53516Better Auth: Account takeover via OAuth auto-link to unverified pre-registered emailbetter-auth
CVE-2026-53515Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/ssobetter-auth; @better-auth sso
CVE-2026-53514Better Auth: Unauthorized invitation acceptance via unverified email match in organization pluginbetter-auth
CVE-2026-53513Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationbetter-auth; @better-auth sso
CVE-2026-53512Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsbetter-auth
CVE-2026-45364Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotationbetter-auth
CVE-2026-45337Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pendingbetter-auth
CVE-2026-41427Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clientsbetter-auth; better-auth oauth-provider
CVE-2026-15527better-auth better-icons scan_project_icons/sync_icon path traversalbetter-auth better-icons
CVE-2025-53535Better Auth has an Open Redirect Vulnerability in originCheck Middleware Affecting Multiple Routesbetter-auth
33 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.