better-auth
The most comprehensive authentication framework for TypeScript.
Security Advisories for better-auth in npm
High
about 1 month ago
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
npm
better-auth
Low
about 2 months ago
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
npm
@better-auth/scim, better-auth
High
about 2 months ago
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
npm
better-auth, @better-auth/oauth-provider
High
about 2 months ago
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
npm
better-auth, @better-auth/oauth-provider
High
about 2 months ago
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
npm
better-auth
High
about 2 months ago
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
npm
better-auth
High
about 2 months ago
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
npm
better-auth
High
about 2 months ago
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
npm
better-auth
Critical
about 2 months ago
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
npm
better-auth
High
3 months ago
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
npm
better-auth
High
3 months ago
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
npm
better-auth
Moderate
3 months ago
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
npm
better-auth
Critical
5 months ago
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
npm
better-auth
High
8 months ago
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
npm
better-auth
Low
9 months ago
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
npm
better-auth
High
11 months ago
Better Auth: Unauthenticated API key creation through api-key plugin
npm
better-auth
Low
about 1 year ago
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
npm
better-auth
High
over 1 year ago
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
npm
better-auth
Moderate
over 1 year ago
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
npm
better-auth
Moderate
over 1 year ago
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
npm
better-auth
High
over 1 year ago
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
npm
better-auth