7.1
CVE-2026-41427
- EPSS 0.21%
- Veröffentlicht 24.04.2026 19:23:20
- Zuletzt bearbeitet 13.05.2026 19:36:38
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clients
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endpoints did not invoke the hook before persisting new clients. Deployments that configured clientPrivileges to restrict client registration were not actually restricted — any authenticated user could reach the create endpoints and register an OAuth client with attacker-chosen redirect URIs and metadata. This vulnerability is fixed in 1.6.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Better-auth ≫ Better-auth/oauth-provider SwPlatformnode.js Version >= 1.4.9 < 1.6.5
Better-auth ≫ Better-auth/oauth-provider Version1.4.8 Update- SwPlatformnode.js
Better-auth ≫ Better-auth/oauth-provider Version1.4.8 Updatebeta7 SwPlatformnode.js
Better-auth ≫ Better-auth/oauth-provider Version1.7.0 Updatebeta0 SwPlatformnode.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.113 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| security-advisories@github.com | 7.1 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/better-auth/better-auth/security/advisories/GHSA-xr8f-h2gw-9xh6