Where
-Infinity
0

better-auth better-authbetter-auth Stale Sessions Persist After User Deletion

Risk 31
Severity
5.1
First published (updated )

better-auth better-authbetter-auth before 1.6.13 Stored XSS via javascript redirect_uri

Risk 44
Severity
5.1
First published (updated )

npm/@better-auth/ssoBetter Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso

Risk 48
Severity
7.1
First published (updated )

npm/better-authBetter Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption

Risk 59
Severity
7.6
First published (updated )

npm/@better-auth/ssoBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration

Risk 68
Severity
9.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

better-auth Better Auth Node.jsBetter Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forking

Risk 60
Severity
8.1
First published (updated )

npm/better-authBetter Auth: Account takeover via OAuth auto-link to unverified pre-registered email

Risk 67
Severity
8.3
First published (updated )

better-auth Better Auth Node.jsBetter Auth: Unauthorized invitation acceptance via unverified email match in organization plugin

Risk 55
Severity
7.7
First published (updated )

npm/better-authBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Risk 66
Severity
9.1
First published (updated )

npm/better-authBetter Auth: Device authorization approve and deny accept any authenticated session while the user code is pending

Risk 62
Severity
7.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

better-auth Better-auth\/oauth-provider Node.jsBetter Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clients

Risk 40
Severity
7.1
First published (updated )

Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)

First published (updated )
Social
reddit

npm/better-authBeter Auth has an Open Redirect via Scheme-Less Callback Parameter

Risk 30
Severity
6.9
EPSS
0.09%
First published (updated )

npm/better-authBetter Auth has an Open Redirect Vulnerability in Verify Email Endpoint

Risk 79
Severity
7.9
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203