Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: better-auth Clear
ID Title
CVE-2026-53515 Privilege Escalation in @better-auth/sso (CVE-2026-53515)
vulnerability in @better-auth/sso (CVE-2026-53515). Data can be tampered with by attackers. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53518 Vulnerability in @better-auth/oauth-provider (CVE-2026-53518)
vulnerability in @better-auth/oauth-provider (CVE-2026-53518). Confidential information can be exposed externally. Exploitable via `POST /oauth2/token`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53513 Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53517 Vulnerability in @better-auth/oauth-provider (CVE-2026-53517)
vulnerability in @better-auth/oauth-provider (CVE-2026-53517). Confidential information can be exposed externally. Exploitable via `POST /oauth2/token`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53516 Authentication Bypass in better-auth (CVE-2026-53516)
authentication bypass in better-auth (CVE-2026-53516). Confidential information can be exposed externally. Exploitable via ``next``. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53514 Authentication Bypass in better-auth (CVE-2026-53514)
authentication bypass in better-auth (CVE-2026-53514). Confidential information can be exposed externally. Exploitable via ``organization``. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53512 Authentication Bypass in better-auth (CVE-2026-53512)
authentication bypass in better-auth (CVE-2026-53512). Confidential information can be exposed externally. Exploitable via ``oauthApplication``. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-45337 Vulnerability in better-auth (CVE-2026-45337)
vulnerability in better-auth (CVE-2026-45337). Confidential information can be exposed externally. Exploitable via `POST /device/approve`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-41427 Authorization Flaw in better-auth (CVE-2026-41427)
vulnerability in better-auth (CVE-2026-41427). Data can be tampered with by attackers. Mitigation: upgrade to `1.6.5` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →