Vulnerabilidades em better-auth

32 resultados
Análise Vexday

Better-auth apresenta 15 vulnerabilidades catalogadas, com 11 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas; nenhuma está sob exploração em campo até o momento. Três vulnerabilidades críticas relacionadas primariamente a falhas de autenticação (CWE-345) demandam priorização na aplicação de patches, embora a ausência de ataques observados sugira janela de oportunidade para remediação.

CVE-2025-61928CRITICALBetter Auth: Unauthenticated API key creation through api-key pluginEPSS 17.9%CVE-2025-71404MEDIUMbetter-auth before 1.1.16 Reflected XSS via error parameterEPSS 0.4%CVE-2024-56734HIGHBetter Auth has an Open Redirect Vulnerability in Verify Email EndpointEPSS 0.4%CVE-2026-67330CRITICALbetter-auth SCIM 1.4.0-beta.27 through 1.6.21 Account Takeover via Provider-ID CollisionEPSS 0.4%CVE-2025-27143MEDIUMBeter Auth has an Open Redirect via Scheme-Less Callback ParameterEPSS 0.3%CVE-2025-53535LOWBetter Auth has an Open Redirect Vulnerability in originCheck Middleware Affecting Multiple RoutesEPSS 0.3%CVE-2025-71399HIGHBetter Auth before 1.4.5 Path Normalization Bypass via rou3EPSS 0.3%CVE-2026-45364HIGHBetter Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotationEPSS 0.3%CVE-2026-67328HIGH@better-auth/sso before 1.6.21 Account Takeover via SSOEPSS 0.3%CVE-2026-67337HIGHbetter-auth before 1.4.9 Two-Factor Authentication Bypass via session.cookieCacheEPSS 0.3%CVE-2025-71401CRITICALbetter-auth before 1.4.2 basePath Modification DoSEPSS 0.3%CVE-2026-53517HIGHBetter Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family ForkingEPSS 0.2%CVE-2026-67331HIGHbetter-auth SCIM 1.5.0 before 1.7.0-beta.4 Authorization BypassEPSS 0.2%CVE-2025-71403HIGHbetter-auth before 1.1.20 Open Redirect via trustedOrigins BypassEPSS 0.2%CVE-2026-53515HIGHBetter Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/ssoEPSS 0.2%CVE-2026-67327HIGHbetter-auth before 1.6.22 Account Takeover via Magic-Link Email-OTPEPSS 0.2%CVE-2026-53518HIGHBetter Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code RedemptionEPSS 0.2%CVE-2026-53512CRITICALBetter Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsEPSS 0.2%CVE-2026-41427HIGHBetter Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clientsEPSS 0.2%CVE-2025-71402LOWbetter-auth before 1.4.0 Session Revocation via Forged CookieEPSS 0.2%