Junglewise Threat Intelligence

CVE-2026-53512: Better Auth authentication bypass in legacy OIDC and MCP plugins

CVE-2026-53512 · Severity: critical · CVSS 9.1 · Published 2026-07-15

Technologies: better-auth (npm). Vendors: npm, Better-Auth.

Executive brief

Better Auth is a security library used by developers to handle user logins and permissions in TypeScript applications. A flaw in its legacy OIDC and MCP plugins allowed attackers who obtained a refresh token to generate new access tokens without knowing the application's secret key. This could lead to unauthorized account access and the ability for an attacker to maintain a persistent foothold in a user's account even if the original session was intended to be protected.

Technical details

The vulnerability exists in the legacy oidcProvider and mcp plugins of Better Auth. While the library correctly requires a client_secret for the initial authorization_code exchange, it fails to enforce this requirement for the refresh_token grant. An attacker who obtains a valid refresh_token (e.g., via local storage leak or proxy logs) can call the /api/auth/oauth2/token or /api/auth/mcp/token endpoints to obtain new access tokens and rotated refresh tokens by providing only the token and a matching client_id. This bypasses the authentication requirements for confidential clients. The issue is addressed in version 1.6.11 by requiring the client_secret for confidential clients and implementing constant-time string comparisons.

Affected products

  • better-auth better-auth < 1.6.11

Timeline

  • 2026-05-12: patched: Fix committed and version 1.6.11 released.
  • 2026-07-15: disclosed: CVE-2026-53512 published.

References

Related threats