Better Auth vulnerabilities and security advisories
The newest reviewed advisories for better-auth on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.
Get an email when Better Auth has a new one
Email alerts are coming soon. This page updates every hour.
$ latest 22 · 16 critical, high or exploited
- highJul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
- better-auth >= 1.1.3, < 1.6.22 · fixed in 1.6.22
- better-auth >= 1.7.0-beta.0, < 1.7.0-beta.10 · fixed in 1.7.0-beta.10
GHSA-qq9h-g4jm-xgf3prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-qq9h-g4jm-xgf3, severity high What it is: Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in Affected packages: - better-auth: affected versions >= 1.1.3, < 1.6.22. Fixed in 1.6.22. - better-auth: affected versions >= 1.7.0-beta.0, < 1.7.0-beta.10. Fixed in 1.7.0-beta.10. Details: https://github.com/advisories/GHSA-qq9h-g4jm-xgf3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowJul 7, 2026
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
- better-auth >= 0.3.4, < 1.6.11 · fixed in 1.6.11
GHSA-2vg6-77g8-24mpprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-2vg6-77g8-24mp, severity low What it is: Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows Affected packages: - better-auth: affected versions >= 0.3.4, < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-2vg6-77g8-24mp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 7, 2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
- better-auth < 1.6.11 · fixed in 1.6.11
GHSA-7w99-5wm4-3g79CVE-2026-53518prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-7w99-5wm4-3g79 (CVE-2026-53518), severity high What it is: @better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive Affected packages: - better-auth: affected versions < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-7w99-5wm4-3g79 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 7, 2026
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
- better-auth >= 1.4.8-beta.7, < 1.6.0 · fixed in 1.6.0
GHSA-392p-2q2v-4372CVE-2026-53517prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-392p-2q2v-4372 (CVE-2026-53517), severity high What it is: Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption Affected packages: - better-auth: affected versions >= 1.4.8-beta.7, < 1.6.0. Fixed in 1.6.0. Details: https://github.com/advisories/GHSA-392p-2q2v-4372 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 7, 2026
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
- better-auth < 1.6.11 · fixed in 1.6.11
GHSA-9h47-pqcx-hjr4prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-9h47-pqcx-hjr4, severity high What it is: Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default Affected packages: - better-auth: affected versions < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-9h47-pqcx-hjr4 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 7, 2026
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
- better-auth < 1.6.13 · fixed in 1.6.13
- better-auth >= 1.7.0-beta.0, < 1.7.0-beta.4 · fixed in 1.7.0-beta.4
GHSA-86j7-9j95-vpqjprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-86j7-9j95-vpqj, severity high What it is: Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp Affected packages: - better-auth: affected versions < 1.6.13. Fixed in 1.6.13. - better-auth: affected versions >= 1.7.0-beta.0, < 1.7.0-beta.4. Fixed in 1.7.0-beta.4. Details: https://github.com/advisories/GHSA-86j7-9j95-vpqj Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 7, 2026
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
- better-auth < 1.6.11 · fixed in 1.6.11
GHSA-g38m-r43w-p2q7CVE-2026-53516prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-g38m-r43w-p2q7 (CVE-2026-53516), severity high What it is: Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email Affected packages: - better-auth: affected versions < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-g38m-r43w-p2q7 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 7, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
- better-auth < 1.6.11 · fixed in 1.6.11
GHSA-fmh4-wcc4-5jm3CVE-2026-53514prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-fmh4-wcc4-5jm3 (CVE-2026-53514), severity high What it is: Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin Affected packages: - better-auth: affected versions < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-fmh4-wcc4-5jm3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - criticalJul 7, 2026
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
- better-auth < 1.6.11 · fixed in 1.6.11
GHSA-pw9m-5jxm-xr6hCVE-2026-53512prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-pw9m-5jxm-xr6h (CVE-2026-53512), severity critical What it is: Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins Affected packages: - better-auth: affected versions < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-pw9m-5jxm-xr6h Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 4, 2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
- better-auth >= 1.6.0, < 1.6.11 · fixed in 1.6.11
GHSA-cq3f-vc6p-68fhCVE-2026-45337prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-cq3f-vc6p-68fh (CVE-2026-45337), severity high What it is: Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending Affected packages: - better-auth: affected versions >= 1.6.0, < 1.6.11. Fixed in 1.6.11. Details: https://github.com/advisories/GHSA-cq3f-vc6p-68fh Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 15, 2026
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
- better-auth < 1.4.17 · fixed in 1.4.17
- better-auth >= 1.5.0-beta.1, < 1.5.0-beta.9 · fixed in 1.5.0-beta.9
GHSA-p6v2-xcpg-h6xwCVE-2026-45364prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-p6v2-xcpg-h6xw (CVE-2026-45364), severity high What it is: Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation Affected packages: - better-auth: affected versions < 1.4.17. Fixed in 1.4.17. - better-auth: affected versions >= 1.5.0-beta.1, < 1.5.0-beta.9. Fixed in 1.5.0-beta.9. Details: https://github.com/advisories/GHSA-p6v2-xcpg-h6xw Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 15, 2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
- better-auth < 1.6.2 · fixed in 1.6.2
GHSA-wxw3-q3m9-c3jrprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-wxw3-q3m9-c3jr, severity medium What it is: Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE Affected packages: - better-auth: affected versions < 1.6.2. Fixed in 1.6.2. Details: https://github.com/advisories/GHSA-wxw3-q3m9-c3jr Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - criticalApr 3, 2026
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
- better-auth < 1.4.9 · fixed in 1.4.9
GHSA-xg6x-h9c9-2m83prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-xg6x-h9c9-2m83, severity critical What it is: Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache) Affected packages: - better-auth: affected versions < 1.4.9. Fixed in 1.4.9. Details: https://github.com/advisories/GHSA-xg6x-h9c9-2m83 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highDec 16, 2025
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
- better-auth < 1.4.5 · fixed in 1.4.5
GHSA-x732-6j76-qmhmprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-x732-6j76-qmhm, severity high What it is: Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits Affected packages: - better-auth: affected versions < 1.4.5. Fixed in 1.4.5. Details: https://github.com/advisories/GHSA-x732-6j76-qmhm Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highDec 1, 2025
Better Auth affected by external request basePath modification DoS
- better-auth < 1.4.2 · fixed in 1.4.2
GHSA-569q-mpph-wgwwCVE-2025-71401prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-569q-mpph-wgww (CVE-2025-71401), severity high What it is: Better Auth affected by external request basePath modification DoS Affected packages: - better-auth: affected versions < 1.4.2. Fixed in 1.4.2. Details: https://github.com/advisories/GHSA-569q-mpph-wgww Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowNov 26, 2025
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
- better-auth >= 1.3.34, < 1.4.0 · fixed in 1.4.0
GHSA-wmjr-v86c-m9jjprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-wmjr-v86c-m9jj, severity low What it is: Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions Affected packages: - better-auth: affected versions >= 1.3.34, < 1.4.0. Fixed in 1.4.0. Details: https://github.com/advisories/GHSA-wmjr-v86c-m9jj Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highOct 9, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
- better-auth < 1.3.26 · fixed in 1.3.26
GHSA-99h5-pjcv-gr6vCVE-2025-61928prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-99h5-pjcv-gr6v (CVE-2025-61928), severity high What it is: Better Auth: Unauthenticated API key creation through api-key plugin Affected packages: - better-auth: affected versions < 1.3.26. Fixed in 1.3.26. Details: https://github.com/advisories/GHSA-99h5-pjcv-gr6v Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowJul 7, 2025
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
- better-auth <= 1.2.9 · fixed in 1.2.10
GHSA-36rg-gfq2-3h56CVE-2025-53535prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-36rg-gfq2-3h56 (CVE-2025-53535), severity low What it is: Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes Affected packages: - better-auth: affected versions <= 1.2.9. Fixed in 1.2.10. Details: https://github.com/advisories/GHSA-36rg-gfq2-3h56 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highFeb 24, 2025
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
- better-auth <= 1.1.20 · fixed in 1.1.21
GHSA-vp58-j275-797xprompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-vp58-j275-797x, severity high What it is: Better Auth allows bypassing the trustedOrigins Protection which leads to ATO Affected packages: - better-auth: affected versions <= 1.1.20. Fixed in 1.1.21. Details: https://github.com/advisories/GHSA-vp58-j275-797x Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 24, 2025
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
- better-auth < 1.1.20 · fixed in 1.1.20
GHSA-hjpm-7mrm-26w8CVE-2025-27143prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hjpm-7mrm-26w8 (CVE-2025-27143), severity medium What it is: Beter Auth has an Open Redirect via Scheme-Less Callback Parameter Affected packages: - better-auth: affected versions < 1.1.20. Fixed in 1.1.20. Details: https://github.com/advisories/GHSA-hjpm-7mrm-26w8 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 5, 2025
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
- better-auth >= 0.0.2, < 1.1.16 · fixed in 1.1.16
GHSA-9x4v-xfq5-m8x5prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-9x4v-xfq5-m8x5, severity medium What it is: Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting) Affected packages: - better-auth: affected versions >= 0.0.2, < 1.1.16. Fixed in 1.1.16. Details: https://github.com/advisories/GHSA-9x4v-xfq5-m8x5 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highDec 30, 2024
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
- better-auth < 1.1.6 · fixed in 1.1.6
GHSA-8jhw-6pjj-8723CVE-2024-56734prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-8jhw-6pjj-8723 (CVE-2024-56734), severity high What it is: Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint Affected packages: - better-auth: affected versions < 1.1.6. Fixed in 1.1.6. Details: https://github.com/advisories/GHSA-8jhw-6pjj-8723 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now.
From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.
Keeping Better Auth patched
npm audit(orpnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.- Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
- A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.