Executive brief
@better-auth/oauth-provider is a library that handles OAuth 2.0 authentication and token management. The vulnerability allows an attacker who completes an OAuth authorization flow to request access tokens for resource servers that were never authorized by the user. If resource servers rely on token audience claims for access control, an attacker could access protected resources beyond the original authorization scope.
Technical details
The vulnerability is an authorization bypass (CWE-863) in the resource parameter handling (RFC 8707). The oauth-provider accepts resource indicators only at the token endpoint and fails to bind them to the authorization grant. An attacker can complete a normal OAuth authorization flow, then request a JWT access token with an audience (aud claim) targeting any resource in the server's validAudiences allowlist, even if that resource was never approved by the user. The same issue affects refresh tokens: a refresh token from one resource grant can be redeemed for tokens targeting different resources. No user interaction is required beyond completing the initial authorization. The vulnerability is fixed in version 1.7.0-beta.4 and later, but the stable 1.6.x line remains unpatched. The fix is breaking and requires schema migration.
Affected products
- better-auth oauth-provider >=1.4.8, <1.7.0-beta.4
Timeline
- 2026-05-31: disclosed
- 2026-07-07: published