@better-auth/oauth-provider
An oauth provider plugin for Better Auth
Security Advisories for @better-auth/oauth-provider in npm
High
about 1 month ago
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
npm
better-auth, @better-auth/oauth-provider
High
about 1 month ago
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
npm
better-auth, @better-auth/oauth-provider
Moderate
about 1 month ago
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
npm
@better-auth/oauth-provider
High
4 months ago
OAuth 2.1 Provider: Unprivileged users can register OAuth clients
npm
@better-auth/oauth-provider
Potential
High
10 months ago
Better Auth: Unauthenticated API key creation through api-key plugin
npm
better-auth
Potential
Low
about 1 year ago
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
npm
better-auth
Potential
High
over 1 year ago
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
npm
better-auth
Potential
Moderate
over 1 year ago
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
npm
better-auth
Potential
Moderate
over 1 year ago
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
npm
better-auth
Potential
High
over 1 year ago
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
npm
better-auth