npm

better-auth

View on npm registry
23 Total advisories
23 Vulnerabilities
0 Malware

Dependency scanning

Check whether better-auth is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

LOW 3.8
npm

CVE-2026-67334

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

MEDIUM 5.9
npm

GHSA-3q45-2fh7-66cj

Duplicate Advisory: better-auth has an external request basePath modification DoS

UNKNOWN
npm

CVE-2025-71401

Better Auth affected by external request basePath modification DoS

HIGH 8.6
npm

CVE-2025-71399

Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits

UNKNOWN
npm

CVE-2026-67337

Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)

UNKNOWN
npm

CVE-2025-71404

Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)

HIGH 8.7
npm

CVE-2026-67336

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

HIGH 7.7
npm

CVE-2026-67333

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

HIGH 8.3
npm

CVE-2026-67327

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

HIGH 7.1
npm

CVE-2025-71403

Better Auth allows bypassing the trustedOrigins Protection which leads to ATO

UNKNOWN
npm

CVE-2025-71402

Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions

MEDIUM 5.3
npm

CVE-2026-67335

Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE

HIGH 8.1
npm

CVE-2026-53518

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

CRITICAL 9.1
npm

CVE-2026-53512

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

HIGH 8.1
npm

CVE-2026-53517

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

HIGH 8.3
npm

CVE-2026-53516

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

HIGH 7.7
npm

CVE-2026-53514

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

HIGH 7.6
npm

CVE-2026-45337

Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending

HIGH 7.3
npm

CVE-2026-45364

Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation

UNKNOWN
npm

CVE-2024-56734

Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint

UNKNOWN
npm

CVE-2025-27143

Beter Auth has an Open Redirect via Scheme-Less Callback Parameter

HIGH 8.6
npm

CVE-2025-61928

Better Auth: Unauthenticated API key creation through api-key plugin

UNKNOWN
npm

CVE-2025-53535

Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes