CVE-2025-71401
- EPSS 0.26%
- Veröffentlicht 02.08.2026 12:15:23
- Zuletzt bearbeitet 03.08.2026 16:16:26
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base...
CVE-2025-71399
- EPSS 0.31%
- Veröffentlicht 02.08.2026 12:15:22
- Zuletzt bearbeitet 03.08.2026 17:16:28
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (whi...
CVE-2026-67337
- EPSS 0.27%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 19:16:52
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by ...
CVE-2026-67336
- EPSS 0.16%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 16:16:30
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens o...
CVE-2026-67334
- EPSS 0.2%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 19:16:52
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to ...
CVE-2026-67333
- EPSS 0.16%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 20:17:27
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can r...
CVE-2025-71403
- EPSS 0.24%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 19:16:41
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redir...
- EPSS 0.17%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 03.08.2026 17:16:41
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to...
CVE-2026-67327
- EPSS 0.23%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 03.08.2026 19:16:51
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enable...
CVE-2025-71404
- EPSS 0.4%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 03.08.2026 17:16:29
better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker...