CRITICAL9.1CVE-2026-53512Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins from 0, < 1.6.11
HIGH8.6CVE-2025-61928Better Auth: Unauthenticated API key creation through api-key plugin from 0, < 1.3.26
HIGH8.3CVE-2026-53516Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email from 0, < 1.6.11
HIGH8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
from 0, < 1.6.11
HIGH8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
>= 1.4.8-beta.7, < 1.6.0
HIGH7.7Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
from 0, < 1.6.11
HIGH7.6Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
>= 1.6.0, < 1.6.11
HIGH7.3Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
from 0, < 1.4.17
—Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
from 0, < 1.2.10
—Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
from 0, < 1.1.20
—Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
from 0, < 1.1.6