Junglewise Threat Intelligence

Better Auth stored XSS in oidc-provider and mcp plugins

Severity: high · CVSS 7.7 · Published 2026-07-07

Vendors: Better-Auth.

Executive brief

Better Auth is an authentication library for web applications. A security flaw in its OIDC and MCP plugins allows an attacker to inject malicious scripts into the authentication server. If a user interacts with a malicious link and approves a login request, the attacker can execute code in the user's browser to steal session data and take over their account.

Technical details

A stored DOM cross-site scripting (XSS) vulnerability exists in the deprecated `oidc-provider` and `mcp` plugins of Better Auth. The root cause is a lack of scheme validation for `redirect_uris` during OAuth client registration, allowing attackers to store `javascript:` URIs. When a victim completes an OAuth consent flow, the authorization server returns this malicious URI. If the client-side consent page assigns this URI to a navigation target like `window.location.href`, the script executes in the context of the authorization server's origin. This allows attackers to access session-scoped endpoints and perform account takeover. The vulnerability is mitigated in the newer `@better-auth/oauth-provider` package which uses `SafeUrlSchema`.

Affected products

  • Better Auth better-auth < 1.6.13, >= 1.7.0-beta.0, < 1.7.0-beta.4

Timeline

  • 2026-05-31: disclosed
  • 2026-07-07: advisory
  • 2026-07-07: patched

References