Vulnerabilities in better-auth
32 resultsVexday analysis
Better-auth apresenta 15 vulnerabilidades catalogadas, com 11 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas; nenhuma está sob exploração em campo até o momento. Três vulnerabilidades críticas relacionadas primariamente a falhas de autenticação (CWE-345) demandam priorização na aplicação de patches, embora a ausência de ataques observados sugira janela de oportunidade para remediação.
CVE-2025-71400HIGHbetter-auth passkey before 1.4.0 IDOR via delete-passkeyEPSS 0.2%CVE-2026-67334MEDIUMbetter-auth Stale Sessions Persist After User DeletionEPSS 0.2%CVE-2026-67329HIGH@better-auth/stripe before 1.6.21 Authorization Bypass via Organization SubscriptionEPSS 0.2%CVE-2026-53513CRITICALBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationEPSS 0.2%CVE-2026-67335MEDIUMbetter-auth before 1.6.2 OAuth State Validation BypassEPSS 0.2%CVE-2026-67332MEDIUM@better-auth/oauth-provider before 1.7.0-beta.4 Authorization BypassEPSS 0.2%CVE-2026-67336CRITICALbetter-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProviderEPSS 0.2%CVE-2026-67333MEDIUMbetter-auth before 1.6.13 Stored XSS via javascript redirect_uriEPSS 0.2%CVE-2026-53516HIGHBetter Auth: Account takeover via OAuth auto-link to unverified pre-registered emailEPSS 0.2%CVE-2026-15527MEDIUMbetter-auth better-icons scan_project_icons/sync_icon path traversalEPSS 0.1%CVE-2026-45337HIGHBetter Auth: Device authorization approve and deny accept any authenticated session while the user code is pendingEPSS 0.1%CVE-2026-53514HIGHBetter Auth: Unauthorized invitation acceptance via unverified email match in organization pluginEPSS 0.1%