{"schema_version":1,"title":"better-auth (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in better-auth (npm): 0 in the last 7 days and 16 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, better-auth basePath modification denial of service, was published on 2 August 2026.","url":"https://junglewise.ai/threats/technologies/better-auth","json_url":"https://junglewise.ai/threats/technologies/better-auth.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/better-auth","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":24,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":16,"last_365_days":19},"latest":[{"cvss":5.9,"slug":"better-auth-basepath-modification-denial-of-service-f80487f6","title":"better-auth basePath modification denial of service","severity":"medium","exploited":false,"published_at":"2026-08-02T15:30:21+00:00","url":"https://junglewise.ai/threats/better-auth-basepath-modification-denial-of-service-f80487f6"},{"cvss":3.1,"slug":"better-auth-external-request-basepath-modification-dos-644481c4","title":"better-auth external request basePath modification DoS","severity":"low","exploited":false,"published_at":"2026-08-02T15:30:21+00:00","url":"https://junglewise.ai/threats/better-auth-external-request-basepath-modification-dos-644481c4"},{"cve":"CVE-2025-71401","cvss":5.9,"epss":0.0046,"slug":"cve-2025-71401-better-auth-router-basepath-dos-via-untrusted-forwarded-headers","title":"better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is un","severity":"high","exploited":false,"published_at":"2026-08-02T13:16:52.53+00:00","url":"https://junglewise.ai/threats/cve-2025-71401-better-auth-router-basepath-dos-via-untrusted-forwarded-headers"},{"cve":"CVE-2025-71399","cvss":8.6,"epss":0.0052,"slug":"cve-2025-71399-better-auth-path-normalization-bypass-of-disabledpaths-and-rate","title":"Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty","severity":"high","exploited":false,"published_at":"2026-08-02T13:16:52.21+00:00","url":"https://junglewise.ai/threats/cve-2025-71399-better-auth-path-normalization-bypass-of-disabledpaths-and-rate"},{"cve":"CVE-2026-67337","cvss":6.5,"epss":0.0046,"slug":"cve-2026-67337-better-auth-two-factor-authentication-bypass-via-premature","title":"better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers wi","severity":"medium","exploited":false,"published_at":"2026-08-01T13:17:04.693+00:00","url":"https://junglewise.ai/threats/cve-2026-67337-better-auth-two-factor-authentication-bypass-via-premature"},{"cve":"CVE-2026-67336","cvss":8.7,"epss":0.0024,"slug":"cve-2026-67336-better-auth-insecure-cryptographic-defaults-in-oidcprovider","title":"better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algor","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:04.557+00:00","url":"https://junglewise.ai/threats/cve-2026-67336-better-auth-insecure-cryptographic-defaults-in-oidcprovider"},{"cve":"CVE-2026-67335","cvss":5.3,"epss":0.0028,"slug":"cve-2026-67335-better-auth-oauth-state-validation-bypass-in-cookie-backed","title":"better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage","severity":"medium","exploited":false,"published_at":"2026-08-01T13:17:04.403+00:00","url":"https://junglewise.ai/threats/cve-2026-67335-better-auth-oauth-state-validation-bypass-in-cookie-backed"},{"cve":"CVE-2026-67334","cvss":3.8,"epss":0.0032,"slug":"cve-2026-67334-better-auth-stale-sessions-after-user-deletion-in-secondary","title":"better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondary","severity":"low","exploited":false,"published_at":"2026-08-01T13:17:04.263+00:00","url":"https://junglewise.ai/threats/cve-2026-67334-better-auth-stale-sessions-after-user-deletion-in-secondary"},{"cve":"CVE-2026-53518","cvss":8.1,"epss":0.0041,"slug":"cve-2026-53518-better-auth-race-condition-in-oauth-authorization-code-redemption","title":"Better Auth race condition in OAuth authorization code redemption","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:48.24+00:00","url":"https://junglewise.ai/threats/cve-2026-53518-better-auth-race-condition-in-oauth-authorization-code-redemption"},{"cve":"CVE-2026-53517","cvss":8.1,"epss":0.0042,"slug":"cve-2026-53517-better-auth-race-condition-in-oauth-refresh-token-rotation","title":"Better Auth race condition in OAuth refresh token rotation","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:48.107+00:00","url":"https://junglewise.ai/threats/cve-2026-53517-better-auth-race-condition-in-oauth-refresh-token-rotation"},{"cve":"CVE-2026-53516","cvss":8.3,"epss":0.0029,"slug":"cve-2026-53516-better-auth-improper-authentication-in-oauth-account-linking","title":"Better Auth improper authentication in OAuth account linking","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:47.967+00:00","url":"https://junglewise.ai/threats/cve-2026-53516-better-auth-improper-authentication-in-oauth-account-linking"},{"cve":"CVE-2026-53514","cvss":7.7,"epss":0.002,"slug":"cve-2026-53514-better-auth-improper-authentication-in-organization-invitation","title":"Better Auth improper authentication in organization invitation endpoints","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:47.683+00:00","url":"https://junglewise.ai/threats/cve-2026-53514-better-auth-improper-authentication-in-organization-invitation"},{"cve":"CVE-2026-53512","cvss":9.1,"epss":0.0028,"slug":"cve-2026-53512-better-auth-authentication-bypass-in-legacy-oidc-and-mcp-plugins","title":"Better Auth authentication bypass in legacy OIDC and MCP plugins","severity":"critical","exploited":false,"published_at":"2026-07-15T18:16:47.42+00:00","url":"https://junglewise.ai/threats/cve-2026-53512-better-auth-authentication-bypass-in-legacy-oidc-and-mcp-plugins"},{"cve":"CVE-2026-45337","cvss":7.6,"epss":0.0021,"slug":"cve-2026-45337-better-auth-authorization-bypass-in-deviceauthorization-plugin","title":"Better Auth authorization bypass in deviceAuthorization plugin","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:45.58+00:00","url":"https://junglewise.ai/threats/cve-2026-45337-better-auth-authorization-bypass-in-deviceauthorization-plugin"},{"cvss":3.8,"slug":"better-auth-stale-session-persistence-after-user-deletion-93ec4b78","title":"Better Auth stale session persistence after user deletion","severity":"low","exploited":false,"published_at":"2026-07-07T20:56:45+00:00","url":"https://junglewise.ai/threats/better-auth-stale-session-persistence-after-user-deletion-93ec4b78"},{"cvss":8.7,"slug":"better-auth-insecure-cryptographic-defaults-in-oidc-and-mcp-plugins-8493304b","title":"Better Auth insecure cryptographic defaults in OIDC and MCP plugins","severity":"high","exploited":false,"published_at":"2026-07-07T20:55:41+00:00","url":"https://junglewise.ai/threats/better-auth-insecure-cryptographic-defaults-in-oidc-and-mcp-plugins-8493304b"},{"cvss":5.3,"slug":"better-auth-csrf-in-oauth-callback-when-using-cookie-storage-10720e2b","title":"Better Auth CSRF in OAuth callback when using cookie storage","severity":"medium","exploited":false,"published_at":"2026-05-15T17:33:40+00:00","url":"https://junglewise.ai/threats/better-auth-csrf-in-oauth-callback-when-using-cookie-storage-10720e2b"},{"cve":"CVE-2025-71402","cvss":4,"epss":0.0027,"slug":"cve-2025-71402-better-auth-multi-session-cookie-signature-bypass","title":"Better Auth multi-session cookie signature bypass","severity":"medium","exploited":false,"published_at":"2025-11-26T22:11:50+00:00","url":"https://junglewise.ai/threats/cve-2025-71402-better-auth-multi-session-cookie-signature-bypass"},{"cve":"CVE-2025-61928","cvss":3.1,"epss":0.1793,"slug":"cve-2025-61928-better-auth-unauthenticated-api-key-creation-in-api-key-plugin","title":"Better Auth unauthenticated API key creation in api-key plugin","severity":"low","exploited":false,"published_at":"2025-10-09T15:40:50+00:00","url":"https://junglewise.ai/threats/cve-2025-61928-better-auth-unauthenticated-api-key-creation-in-api-key-plugin"},{"cve":"CVE-2025-53535","cvss":4,"slug":"cve-2025-53535-better-auth-open-redirect-in-origincheck-middleware","title":"Better Auth open redirect in originCheck middleware","severity":"medium","exploited":false,"published_at":"2025-07-07T22:13:14+00:00","url":"https://junglewise.ai/threats/cve-2025-53535-better-auth-open-redirect-in-origincheck-middleware"},{"cve":"CVE-2025-71403","cvss":3.1,"epss":0.0034,"slug":"cve-2025-71403-better-auth-trustedorigins-bypass-leading-to-account-takeover","title":"Better Auth trustedOrigins bypass leading to account takeover","severity":"low","exploited":false,"published_at":"2025-02-24T20:49:50+00:00","url":"https://junglewise.ai/threats/cve-2025-71403-better-auth-trustedorigins-bypass-leading-to-account-takeover"},{"cve":"CVE-2025-27143","cvss":4,"epss":0.0035,"slug":"cve-2025-27143-better-auth-open-redirect-via-scheme-less-callback-parameter","title":"Better Auth open redirect via scheme-less callback parameter","severity":"medium","exploited":false,"published_at":"2025-02-24T18:27:55+00:00","url":"https://junglewise.ai/threats/cve-2025-27143-better-auth-open-redirect-via-scheme-less-callback-parameter"},{"cve":"CVE-2025-71404","cvss":4,"epss":0.0052,"slug":"cve-2025-71404-better-auth-reflected-cross-site-scripting-in-error-page","title":"Better Auth reflected cross-site scripting in error page","severity":"medium","exploited":false,"published_at":"2025-02-05T21:49:39+00:00","url":"https://junglewise.ai/threats/cve-2025-71404-better-auth-reflected-cross-site-scripting-in-error-page"},{"cve":"CVE-2024-56734","cvss":4,"epss":0.004,"slug":"cve-2024-56734-better-auth-open-redirect-in-verify-email-endpoint","title":"Better Auth open redirect in verify email endpoint","severity":"medium","exploited":false,"published_at":"2024-12-30T16:49:12+00:00","url":"https://junglewise.ai/threats/cve-2024-56734-better-auth-open-redirect-in-verify-email-endpoint"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":6},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"astro (npm)","slug":"astro","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/astro"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"}],"technology":{"hub":true,"name":"better-auth (npm)","slug":"better-auth","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://www.better-auth.com/","repo_url":"https://github.com/better-auth/better-auth","description":"A framework-agnostic authentication library for TypeScript applications.","url":"https://junglewise.ai/threats/technologies/better-auth"},"most_severe":[{"cve":"CVE-2026-53512","cvss":9.1,"epss":0.0028,"slug":"cve-2026-53512-better-auth-authentication-bypass-in-legacy-oidc-and-mcp-plugins","title":"Better Auth authentication bypass in legacy OIDC and MCP plugins","severity":"critical","exploited":false,"published_at":"2026-07-15T18:16:47.42+00:00","url":"https://junglewise.ai/threats/cve-2026-53512-better-auth-authentication-bypass-in-legacy-oidc-and-mcp-plugins"},{"cve":"CVE-2026-67336","cvss":8.7,"epss":0.0024,"slug":"cve-2026-67336-better-auth-insecure-cryptographic-defaults-in-oidcprovider","title":"better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algor","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:04.557+00:00","url":"https://junglewise.ai/threats/cve-2026-67336-better-auth-insecure-cryptographic-defaults-in-oidcprovider"},{"cvss":8.7,"slug":"better-auth-insecure-cryptographic-defaults-in-oidc-and-mcp-plugins-8493304b","title":"Better Auth insecure cryptographic defaults in OIDC and MCP plugins","severity":"high","exploited":false,"published_at":"2026-07-07T20:55:41+00:00","url":"https://junglewise.ai/threats/better-auth-insecure-cryptographic-defaults-in-oidc-and-mcp-plugins-8493304b"},{"cve":"CVE-2025-71399","cvss":8.6,"epss":0.0052,"slug":"cve-2025-71399-better-auth-path-normalization-bypass-of-disabledpaths-and-rate","title":"Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty","severity":"high","exploited":false,"published_at":"2026-08-02T13:16:52.21+00:00","url":"https://junglewise.ai/threats/cve-2025-71399-better-auth-path-normalization-bypass-of-disabledpaths-and-rate"},{"cve":"CVE-2026-53516","cvss":8.3,"epss":0.0029,"slug":"cve-2026-53516-better-auth-improper-authentication-in-oauth-account-linking","title":"Better Auth improper authentication in OAuth account linking","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:47.967+00:00","url":"https://junglewise.ai/threats/cve-2026-53516-better-auth-improper-authentication-in-oauth-account-linking"},{"cve":"CVE-2026-53517","cvss":8.1,"epss":0.0042,"slug":"cve-2026-53517-better-auth-race-condition-in-oauth-refresh-token-rotation","title":"Better Auth race condition in OAuth refresh token rotation","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:48.107+00:00","url":"https://junglewise.ai/threats/cve-2026-53517-better-auth-race-condition-in-oauth-refresh-token-rotation"},{"cve":"CVE-2026-53518","cvss":8.1,"epss":0.0041,"slug":"cve-2026-53518-better-auth-race-condition-in-oauth-authorization-code-redemption","title":"Better Auth race condition in OAuth authorization code redemption","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:48.24+00:00","url":"https://junglewise.ai/threats/cve-2026-53518-better-auth-race-condition-in-oauth-authorization-code-redemption"},{"cve":"CVE-2026-53514","cvss":7.7,"epss":0.002,"slug":"cve-2026-53514-better-auth-improper-authentication-in-organization-invitation","title":"Better Auth improper authentication in organization invitation endpoints","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:47.683+00:00","url":"https://junglewise.ai/threats/cve-2026-53514-better-auth-improper-authentication-in-organization-invitation"},{"cve":"CVE-2026-45337","cvss":7.6,"epss":0.0021,"slug":"cve-2026-45337-better-auth-authorization-bypass-in-deviceauthorization-plugin","title":"Better Auth authorization bypass in deviceAuthorization plugin","severity":"high","exploited":false,"published_at":"2026-07-15T18:16:45.58+00:00","url":"https://junglewise.ai/threats/cve-2026-45337-better-auth-authorization-bypass-in-deviceauthorization-plugin"},{"cve":"CVE-2025-71401","cvss":5.9,"epss":0.0046,"slug":"cve-2025-71401-better-auth-router-basepath-dos-via-untrusted-forwarded-headers","title":"better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is un","severity":"high","exploited":false,"published_at":"2026-08-02T13:16:52.53+00:00","url":"https://junglewise.ai/threats/cve-2025-71401-better-auth-router-basepath-dos-via-untrusted-forwarded-headers"}],"generated_at":"2026-09-26T10:14:00.201383+00:00"}