Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Modified: 9/10/2026
package
pkg:npm/better-auth
Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows
Modified: 9/10/2026
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Modified: 7/7/2025
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Modified: 7/20/2026
Better Auth affected by external request basePath modification DoS
Modified: 9/1/2026
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
Modified: 7/20/2026
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
Modified: 8/2/2026
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
Modified: 2/4/2026
Better Auth: Unauthenticated API key creation through api-key plugin
Modified: 12/9/2025
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
Modified: 8/2/2026
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
Modified: 8/2/2026
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
Modified: 6/9/2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
Modified: 7/20/2026
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
Modified: 7/20/2026
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
Modified: 2/4/2026
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
Modified: 6/9/2026
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Modified: 7/20/2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
Modified: 8/2/2026
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
Modified: 8/2/2026
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
Modified: 8/2/2026
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
Modified: 8/2/2026
Better Auth's rou3 Dependency has Double-Slash Path Normalization which can Bypass disabledPaths Config and Rate Limits
Modified: 8/3/2026
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
Modified: 8/2/2026