HIGH8.1npm
GHSA-392p-2q2v-4372· CVE-2026-53517Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Modified: 7/20/2026
package
pkg:npm/%40better-auth/oauth-provider
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Modified: 7/20/2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
Modified: 7/20/2026
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
Modified: 9/10/2026
OAuth 2.1 Provider: Unprivileged users can register OAuth clients
Modified: 5/5/2026