Better Auth
Vendor:
First CVE: Dec 30, 2024 · Active for 1 year
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Better Auth over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2024
18 months ago
Most Recent CVE
Jul 15, 2026
9 days ago
CVE Severity & Scoring
Better Auth10 CVEs
20%
60%
20%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None4 (40.0%)
Unknown0 (0.0%)
Required6 (60.0%)
Privileges Required
Low5 (50.0%)
High0 (0.0%)
None5 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53513CRITICAL Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-53512CRITICAL Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token | Jul 15, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-53517HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refres | Jul 15, 2026 | 8.1 | 37 | NO | NO |
CVE-2026-53516HIGH Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit acco | Jul 15, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-45337HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of | Jul 15, 2026 | 7.6 | 33 | NO | NO |
CVE-2026-53514HIGH Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox | Jul 15, 2026 | 7.7 | 33 | NO | NO |
CVE-2026-53518HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorizatio | Jul 15, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-53515HIGH Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization | Jul 15, 2026 | 7.1 | 32 | NO | NO |
CVE-2025-27143MEDIUM Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of | Feb 24, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-56734MEDIUM Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1. | Dec 30, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Better Auth
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.4.8 | 1 | 8.1 | 0.4% | 0 | 0 |