Dependency scanning
Check whether better-auth is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-67334
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
GHSA-3q45-2fh7-66cj
Duplicate Advisory: better-auth has an external request basePath modification DoS
CVE-2025-71401
Better Auth affected by external request basePath modification DoS
CVE-2025-71399
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
CVE-2026-67337
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
CVE-2025-71404
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
CVE-2026-67336
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
CVE-2026-67333
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
CVE-2026-67327
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
CVE-2025-71403
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
CVE-2025-71402
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
CVE-2026-67335
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
CVE-2026-53518
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
CVE-2026-53512
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
CVE-2026-53517
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
CVE-2026-53516
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
CVE-2026-53514
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
CVE-2026-45337
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
CVE-2026-45364
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
CVE-2024-56734
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
CVE-2025-27143
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
CVE-2025-61928
Better Auth: Unauthenticated API key creation through api-key plugin
CVE-2025-53535
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes