pwnmyvibecode_

Better Auth vulnerabilities and security advisories

The newest reviewed advisories for better-auth on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.

Get an email when Better Auth has a new one

Email alerts are coming soon. This page updates every hour.

$ latest 22 · 16 critical, high or exploited

  • highJul 24, 2026

    Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

    • better-auth >= 1.1.3, < 1.6.22 · fixed in 1.6.22
    • better-auth >= 1.7.0-beta.0, < 1.7.0-beta.10 · fixed in 1.7.0-beta.10
    GHSA-qq9h-g4jm-xgf3
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-qq9h-g4jm-xgf3, severity high
    What it is: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
    Affected packages:
    - better-auth: affected versions >= 1.1.3, < 1.6.22. Fixed in 1.6.22.
    - better-auth: affected versions >= 1.7.0-beta.0, < 1.7.0-beta.10. Fixed in 1.7.0-beta.10.
    Details: https://github.com/advisories/GHSA-qq9h-g4jm-xgf3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowJul 7, 2026

    Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

    • better-auth >= 0.3.4, < 1.6.11 · fixed in 1.6.11
    GHSA-2vg6-77g8-24mp
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-2vg6-77g8-24mp, severity low
    What it is: Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
    Affected packages:
    - better-auth: affected versions >= 0.3.4, < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-2vg6-77g8-24mp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJul 7, 2026

    @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

    • better-auth < 1.6.11 · fixed in 1.6.11
    GHSA-7w99-5wm4-3g79CVE-2026-53518
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-7w99-5wm4-3g79 (CVE-2026-53518), severity high
    What it is: @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
    Affected packages:
    - better-auth: affected versions < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-7w99-5wm4-3g79
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJul 7, 2026

    Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

    • better-auth >= 1.4.8-beta.7, < 1.6.0 · fixed in 1.6.0
    GHSA-392p-2q2v-4372CVE-2026-53517
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-392p-2q2v-4372 (CVE-2026-53517), severity high
    What it is: Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
    Affected packages:
    - better-auth: affected versions >= 1.4.8-beta.7, < 1.6.0. Fixed in 1.6.0.
    Details: https://github.com/advisories/GHSA-392p-2q2v-4372
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJul 7, 2026

    Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

    • better-auth < 1.6.11 · fixed in 1.6.11
    GHSA-9h47-pqcx-hjr4
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-9h47-pqcx-hjr4, severity high
    What it is: Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
    Affected packages:
    - better-auth: affected versions < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-9h47-pqcx-hjr4
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJul 7, 2026

    Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp

    • better-auth < 1.6.13 · fixed in 1.6.13
    • better-auth >= 1.7.0-beta.0, < 1.7.0-beta.4 · fixed in 1.7.0-beta.4
    GHSA-86j7-9j95-vpqj
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-86j7-9j95-vpqj, severity high
    What it is: Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
    Affected packages:
    - better-auth: affected versions < 1.6.13. Fixed in 1.6.13.
    - better-auth: affected versions >= 1.7.0-beta.0, < 1.7.0-beta.4. Fixed in 1.7.0-beta.4.
    Details: https://github.com/advisories/GHSA-86j7-9j95-vpqj
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJul 7, 2026

    Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

    • better-auth < 1.6.11 · fixed in 1.6.11
    GHSA-g38m-r43w-p2q7CVE-2026-53516
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-g38m-r43w-p2q7 (CVE-2026-53516), severity high
    What it is: Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
    Affected packages:
    - better-auth: affected versions < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-g38m-r43w-p2q7
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJul 7, 2026

    Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

    • better-auth < 1.6.11 · fixed in 1.6.11
    GHSA-fmh4-wcc4-5jm3CVE-2026-53514
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-fmh4-wcc4-5jm3 (CVE-2026-53514), severity high
    What it is: Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
    Affected packages:
    - better-auth: affected versions < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-fmh4-wcc4-5jm3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • criticalJul 7, 2026

    Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

    • better-auth < 1.6.11 · fixed in 1.6.11
    GHSA-pw9m-5jxm-xr6hCVE-2026-53512
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-pw9m-5jxm-xr6h (CVE-2026-53512), severity critical
    What it is: Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
    Affected packages:
    - better-auth: affected versions < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-pw9m-5jxm-xr6h
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJun 4, 2026

    Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending

    • better-auth >= 1.6.0, < 1.6.11 · fixed in 1.6.11
    GHSA-cq3f-vc6p-68fhCVE-2026-45337
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-cq3f-vc6p-68fh (CVE-2026-45337), severity high
    What it is: Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
    Affected packages:
    - better-auth: affected versions >= 1.6.0, < 1.6.11. Fixed in 1.6.11.
    Details: https://github.com/advisories/GHSA-cq3f-vc6p-68fh
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 15, 2026

    Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation

    • better-auth < 1.4.17 · fixed in 1.4.17
    • better-auth >= 1.5.0-beta.1, < 1.5.0-beta.9 · fixed in 1.5.0-beta.9
    GHSA-p6v2-xcpg-h6xwCVE-2026-45364
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-p6v2-xcpg-h6xw (CVE-2026-45364), severity high
    What it is: Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
    Affected packages:
    - better-auth: affected versions < 1.4.17. Fixed in 1.4.17.
    - better-auth: affected versions >= 1.5.0-beta.1, < 1.5.0-beta.9. Fixed in 1.5.0-beta.9.
    Details: https://github.com/advisories/GHSA-p6v2-xcpg-h6xw
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 15, 2026

    Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE

    • better-auth < 1.6.2 · fixed in 1.6.2
    GHSA-wxw3-q3m9-c3jr
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-wxw3-q3m9-c3jr, severity medium
    What it is: Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
    Affected packages:
    - better-auth: affected versions < 1.6.2. Fixed in 1.6.2.
    Details: https://github.com/advisories/GHSA-wxw3-q3m9-c3jr
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • criticalApr 3, 2026

    Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)

    • better-auth < 1.4.9 · fixed in 1.4.9
    GHSA-xg6x-h9c9-2m83
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-xg6x-h9c9-2m83, severity critical
    What it is: Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
    Affected packages:
    - better-auth: affected versions < 1.4.9. Fixed in 1.4.9.
    Details: https://github.com/advisories/GHSA-xg6x-h9c9-2m83
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highDec 16, 2025

    Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits

    • better-auth < 1.4.5 · fixed in 1.4.5
    GHSA-x732-6j76-qmhm
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-x732-6j76-qmhm, severity high
    What it is: Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
    Affected packages:
    - better-auth: affected versions < 1.4.5. Fixed in 1.4.5.
    Details: https://github.com/advisories/GHSA-x732-6j76-qmhm
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highDec 1, 2025

    Better Auth affected by external request basePath modification DoS

    • better-auth < 1.4.2 · fixed in 1.4.2
    GHSA-569q-mpph-wgwwCVE-2025-71401
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-569q-mpph-wgww (CVE-2025-71401), severity high
    What it is: Better Auth affected by external request basePath modification DoS
    Affected packages:
    - better-auth: affected versions < 1.4.2. Fixed in 1.4.2.
    Details: https://github.com/advisories/GHSA-569q-mpph-wgww
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowNov 26, 2025

    Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions

    • better-auth >= 1.3.34, < 1.4.0 · fixed in 1.4.0
    GHSA-wmjr-v86c-m9jj
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-wmjr-v86c-m9jj, severity low
    What it is: Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
    Affected packages:
    - better-auth: affected versions >= 1.3.34, < 1.4.0. Fixed in 1.4.0.
    Details: https://github.com/advisories/GHSA-wmjr-v86c-m9jj
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highOct 9, 2025

    Better Auth: Unauthenticated API key creation through api-key plugin

    • better-auth < 1.3.26 · fixed in 1.3.26
    GHSA-99h5-pjcv-gr6vCVE-2025-61928
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-99h5-pjcv-gr6v (CVE-2025-61928), severity high
    What it is: Better Auth: Unauthenticated API key creation through api-key plugin
    Affected packages:
    - better-auth: affected versions < 1.3.26. Fixed in 1.3.26.
    Details: https://github.com/advisories/GHSA-99h5-pjcv-gr6v
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowJul 7, 2025

    Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes

    • better-auth <= 1.2.9 · fixed in 1.2.10
    GHSA-36rg-gfq2-3h56CVE-2025-53535
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-36rg-gfq2-3h56 (CVE-2025-53535), severity low
    What it is: Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
    Affected packages:
    - better-auth: affected versions <= 1.2.9. Fixed in 1.2.10.
    Details: https://github.com/advisories/GHSA-36rg-gfq2-3h56
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highFeb 24, 2025

    Better Auth allows bypassing the trustedOrigins Protection which leads to ATO

    • better-auth <= 1.1.20 · fixed in 1.1.21
    GHSA-vp58-j275-797x
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-vp58-j275-797x, severity high
    What it is: Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
    Affected packages:
    - better-auth: affected versions <= 1.1.20. Fixed in 1.1.21.
    Details: https://github.com/advisories/GHSA-vp58-j275-797x
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 24, 2025

    Beter Auth has an Open Redirect via Scheme-Less Callback Parameter

    • better-auth < 1.1.20 · fixed in 1.1.20
    GHSA-hjpm-7mrm-26w8CVE-2025-27143
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hjpm-7mrm-26w8 (CVE-2025-27143), severity medium
    What it is: Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
    Affected packages:
    - better-auth: affected versions < 1.1.20. Fixed in 1.1.20.
    Details: https://github.com/advisories/GHSA-hjpm-7mrm-26w8
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumFeb 5, 2025

    Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)

    • better-auth >= 0.0.2, < 1.1.16 · fixed in 1.1.16
    GHSA-9x4v-xfq5-m8x5
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-9x4v-xfq5-m8x5, severity medium
    What it is: Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
    Affected packages:
    - better-auth: affected versions >= 0.0.2, < 1.1.16. Fixed in 1.1.16.
    Details: https://github.com/advisories/GHSA-9x4v-xfq5-m8x5
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highDec 30, 2024

    Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint

    • better-auth < 1.1.6 · fixed in 1.1.6
    GHSA-8jhw-6pjj-8723CVE-2024-56734
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-8jhw-6pjj-8723 (CVE-2024-56734), severity high
    What it is: Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
    Affected packages:
    - better-auth: affected versions < 1.1.6. Fixed in 1.1.6.
    Details: https://github.com/advisories/GHSA-8jhw-6pjj-8723
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.

From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.

Keeping Better Auth patched

  • npm audit (or pnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.
  • Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
  • A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.