Technology · npm
better-auth (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in better-auth (npm): 0 in the last 7 days and 16 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, better-auth basePath modification denial of service, was published on 2 August 2026.
- Last 7 days
- 0
- Last 90 days
- 16
- Critical, all time
- 1
- Exploited in the wild
- 0
About better-auth (npm)
A framework-agnostic authentication library for TypeScript applications.
Latest better-auth (npm) vulnerabilities
- better-auth basePath modification denial of servicemediumCVSS 5.9
- better-auth external request basePath modification DoSlowCVSS 3.1
- CVE-2025-71401: better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g…highCVSS 5.9EPSS 0.5%
- CVE-2025-71399: Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized…highCVSS 8.6EPSS 0.5%
- CVE-2026-67337: better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-67336: better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that…highCVSS 8.7EPSS 0.2%
- CVE-2026-67335: better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-67334: better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM…lowCVSS 3.8EPSS 0.3%
- CVE-2026-53518: Better Auth race condition in OAuth authorization code redemptionhighCVSS 8.1EPSS 0.4%
- CVE-2026-53517: Better Auth race condition in OAuth refresh token rotationhighCVSS 8.1EPSS 0.4%
- CVE-2026-53516: Better Auth improper authentication in OAuth account linkinghighCVSS 8.3EPSS 0.3%
- CVE-2026-53514: Better Auth improper authentication in organization invitation endpointshighCVSS 7.7EPSS 0.2%
- CVE-2026-53512: Better Auth authentication bypass in legacy OIDC and MCP pluginscriticalCVSS 9.1EPSS 0.3%
- CVE-2026-45337: Better Auth authorization bypass in deviceAuthorization pluginhighCVSS 7.6EPSS 0.2%
- Better Auth stale session persistence after user deletionlowCVSS 3.8
- Better Auth insecure cryptographic defaults in OIDC and MCP pluginshighCVSS 8.7
- Better Auth CSRF in OAuth callback when using cookie storagemediumCVSS 5.3
- CVE-2025-71402: Better Auth multi-session cookie signature bypassmediumCVSS 4EPSS 0.3%
- CVE-2025-61928: Better Auth unauthenticated API key creation in api-key pluginlowCVSS 3.1EPSS 17.9%
- CVE-2025-53535: Better Auth open redirect in originCheck middlewaremediumCVSS 4
- CVE-2025-71403: Better Auth trustedOrigins bypass leading to account takeoverlowCVSS 3.1EPSS 0.3%
- CVE-2025-27143: Better Auth open redirect via scheme-less callback parametermediumCVSS 4EPSS 0.4%
- CVE-2025-71404: Better Auth reflected cross-site scripting in error pagemediumCVSS 4EPSS 0.5%
- CVE-2024-56734: Better Auth open redirect in verify email endpointmediumCVSS 4EPSS 0.4%
Most severe better-auth (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-53512: Better Auth authentication bypass in legacy OIDC and MCP pluginscriticalCVSS 9.1EPSS 0.3%
- CVE-2026-67336: better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that…highCVSS 8.7EPSS 0.2%
- Better Auth insecure cryptographic defaults in OIDC and MCP pluginshighCVSS 8.7
- CVE-2025-71399: Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized…highCVSS 8.6EPSS 0.5%
- CVE-2026-53516: Better Auth improper authentication in OAuth account linkinghighCVSS 8.3EPSS 0.3%
- CVE-2026-53517: Better Auth race condition in OAuth refresh token rotationhighCVSS 8.1EPSS 0.4%
- CVE-2026-53518: Better Auth race condition in OAuth authorization code redemptionhighCVSS 8.1EPSS 0.4%
- CVE-2026-53514: Better Auth improper authentication in organization invitation endpointshighCVSS 7.7EPSS 0.2%
- CVE-2026-45337: Better Auth authorization bypass in deviceAuthorization pluginhighCVSS 7.6EPSS 0.2%
- CVE-2025-71401: better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g…highCVSS 5.9EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 6 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 8 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/better-auth.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "better-auth (npm) vulnerabilities", https://junglewise.ai/threats/technologies/better-auth, 26 September 2026.