4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether @better-auth/oauth-provider is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.4
CVE-2026-67332
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
HIGH 8.1
CVE-2026-53518
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
HIGH 8.1
CVE-2026-53517
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
UNKNOWN
CVE-2026-41427
OAuth 2.1 Provider: Unprivileged users can register OAuth clients
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes