Executive brief
Better Auth is an authentication library used by web applications to integrate OAuth login flows. When configured to store OAuth session state in cookies (instead of the default database) and without additional PKCE security, the library fails to properly validate the OAuth state parameter, allowing attackers to trick users into logging in or linking accounts under attacker-controlled identities. This could enable account takeover or persistent unauthorized access.
Technical details
The vulnerability exists in the parseGenericState function's cookie-backed code path, which decrypts and validates the OAuth state cookie expiry but fails to compare the incoming OAuth state query parameter against the nonce stored in the encrypted payload. When PKCE is disabled (pkce: false) or custom token endpoints bypass code-verifier enforcement, an attacker can force a victim's browser to the OAuth callback endpoint with a forged state parameter and attacker-controlled authorization code. Since the cookie validation only checks expiry without verifying state equality, the callback accepts the forged request and mints a session bound to the attacker's external identity. The database-backed strategy (default) is not affected because state verification is enforced by keying the lookup to the state value. The patch (v1.6.2) adds explicit state equality validation in the encrypted cookie payload and applies defense-in-depth checks to all callers including generic OAuth, social login, account-linking, OIDC SSO, and SAML flows.
Affected products
- Better Auth better-auth <1.6.2
Timeline
- 2026-05-15: disclosed: Published as GHSA-wxw3-q3m9-c3jr with CVE-2026-67335
- 2026-04-09: patched: Fixed in v1.6.2 (commit 9deb7936a via PR #8949)