npm

better-auth

View on npm registry
22 Total advisories
22 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
npm

CVE-2025-71401

Better Auth affected by external request basePath modification DoS

HIGH 8.6
npm

CVE-2025-71399

Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits

UNKNOWN
npm

CVE-2026-67337

Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)

LOW 3.8
npm

CVE-2026-67334

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

UNKNOWN
npm

CVE-2025-71404

Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)

HIGH 8.7
npm

CVE-2026-67336

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

HIGH 7.7
npm

CVE-2026-67333

Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

HIGH 8.3
npm

CVE-2026-67327

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

HIGH 7.1
npm

CVE-2025-71403

Better Auth allows bypassing the trustedOrigins Protection which leads to ATO

UNKNOWN
npm

CVE-2025-71402

Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions

MEDIUM 5.3
npm

CVE-2026-67335

Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE

HIGH 8.1
npm

CVE-2026-53518

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

CRITICAL 9.1
npm

CVE-2026-53512

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

HIGH 8.1
npm

CVE-2026-53517

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

HIGH 8.3
npm

CVE-2026-53516

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

HIGH 7.7
npm

CVE-2026-53514

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

HIGH 7.6
npm

CVE-2026-45337

Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending

HIGH 7.3
npm

CVE-2026-45364

Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation

UNKNOWN
npm

CVE-2024-56734

Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint

UNKNOWN
npm

CVE-2025-27143

Beter Auth has an Open Redirect via Scheme-Less Callback Parameter

HIGH 8.6
npm

CVE-2025-61928

Better Auth: Unauthenticated API key creation through api-key plugin

UNKNOWN
npm

CVE-2025-53535

Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes

Ready to move

Start Securing

Free, no credit card | First findings in minutes