Security Advisories for @better-auth/scim in npm
Critical
8 days ago
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
npm
@better-auth/scim
High
24 days ago
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
npm
@better-auth/scim
Low
24 days ago
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
npm
@better-auth/scim, better-auth
Potential
High
10 months ago
Better Auth: Unauthenticated API key creation through api-key plugin
npm
better-auth
Potential
Low
about 1 year ago
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
npm
better-auth
Potential
High
over 1 year ago
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
npm
better-auth
Potential
Moderate
over 1 year ago
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
npm
better-auth
Potential
Moderate
over 1 year ago
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
npm
better-auth
Potential
High
over 1 year ago
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
npm
better-auth