Better Auth is a narrowly focused authentication library or service with a modest footprint in the vulnerability landscape. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Better Auth over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53513CRITICAL Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-53512CRITICAL Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token | Jul 15, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-53517HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refres | Jul 15, 2026 | 8.1 | 37 | NO | NO |
CVE-2026-53516HIGH Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit acco | Jul 15, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-45337HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of | Jul 15, 2026 | 7.6 | 33 | NO | NO |
CVE-2026-53514HIGH Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox | Jul 15, 2026 | 7.7 | 33 | NO | NO |
CVE-2026-53518HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorizatio | Jul 15, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-53515HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization | Jul 15, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-41427MEDIUM Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endp | Apr 24, 2026 | 6.5 | 26 | NO | NO |
CVE-2025-27143MEDIUM Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of | Feb 24, 2025 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Better Auth.
Media articles that mention a CVE ID that affects a product developed by Better Auth — matched by CVE ID, not by vendor name.