VendorsBetter Authbetter_authany version
Vulnerabilities

Better Auth Better Auth any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-53513
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
Published 2026-07-15 · Analyzed
9.6EPSS 0.002
CVE-2026-53512
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Published 2026-07-15 · Analyzed
9.1EPSS 0.003
CVE-2026-53516
Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email
Published 2026-07-15 · Analyzed
8.3EPSS 0.003
CVE-2026-53517
Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forking
Published 2026-07-15 · Analyzed
8.1EPSS 0.004
CVE-2026-53518
Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption
Published 2026-07-15 · Analyzed
8.1EPSS 0.004
CVE-2024-56734
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
Published 2024-12-30 · Analyzed
7.9EPSS 0.004
CVE-2026-53514
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
Published 2026-07-15 · Analyzed
7.7EPSS 0.002
CVE-2026-45337
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
Published 2026-07-15 · Analyzed
7.6EPSS 0.002
CVE-2026-53515
Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso
Published 2026-07-15 · Analyzed
7.1EPSS 0.004
CVE-2025-27143
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
Published 2025-02-24 · Analyzed
6.9EPSS 0.004