Записи better-auth
11 опубликованных записей вендора better-auth.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-269 Improper Privilege Management1
- CWE-285 Improper Authorization1
- CWE-20 Improper Input Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2026-53513Эксплойта нет | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationbetter-auth · better-auth\/sso · CWE-20 | Критическая9,6 | — | 0,2 % | 15 июл. 2026 г. |
36Наблюдать | CVE-2026-53512Эксплойта нет | Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp pluginsbetter-auth · better auth · CWE-287 | Критическая9,1 | — | 0,3 % | 15 июл. 2026 г. |
33Наблюдать | CVE-2026-53516Эксплойта нет | Better Auth: Account takeover via OAuth auto-link to unverified pre-registered emailbetter-auth · better auth · CWE-287 | Высокая8,3 | — | 0,3 % | 15 июл. 2026 г. |
32Наблюдать | CVE-2026-53517Эксплойта нет | Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forkingbetter-auth · better-auth\/oauth-provider · CWE-362 | Высокая8,1 | — | 0,4 % | 15 июл. 2026 г. |
31Наблюдать | CVE-2024-56734Эксплойта нет | Better Auth has an Open Redirect Vulnerability in Verify Email Endpointbetter-auth · better auth · CWE-601 | Высокая7,9 | — | 0,4 % | 30 дек. 2024 г. |
30Наблюдать | CVE-2026-53518Эксплойта нет | Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemptionbetter-auth · better-auth\/oauth-provider · CWE-362 | Высокая7,6 | — | 0,4 % | 15 июл. 2026 г. |
30Наблюдать | CVE-2026-45337Эксплойта нет | Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pendingbetter-auth · better auth · CWE-285 | Высокая7,6 | — | 0,2 % | 15 июл. 2026 г. |
30Наблюдать | CVE-2026-53514Эксплойта нет | Better Auth: Unauthorized invitation acceptance via unverified email match in organization pluginbetter-auth · better auth · CWE-287 | Высокая7,7 | — | 0,2 % | 15 июл. 2026 г. |
28Наблюдать | CVE-2026-53515Эксплойта нет | Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/ssobetter-auth · better-auth\/sso · CWE-269 | Высокая7,1 | — | 0,4 % | 15 июл. 2026 г. |
28Наблюдать | CVE-2026-41427Эксплойта нет | Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clientsbetter-auth · better-auth\/oauth-provider · CWE-863 | Высокая7,1 | — | 0,4 % | 24 апр. 2026 г. |
27Наблюдать | CVE-2025-27143Эксплойта нет | Beter Auth has an Open Redirect via Scheme-Less Callback Parameterbetter-auth · better auth · CWE-601 | Средняя6,9 | — | 0,4 % | 24 февр. 2025 г. |
- CVE-2026-5351338Наблюдать
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %better-auth · better-auth\/sso15 июл. 2026 г.
- CVE-2026-5351236Наблюдать
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %better-auth · better auth15 июл. 2026 г.
- CVE-2026-5351633Наблюдать
Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %better-auth · better auth15 июл. 2026 г.
- CVE-2026-5351732Наблюдать
Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forking
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %better-auth · better-auth\/oauth-provider15 июл. 2026 г.
- CVE-2024-5673431Наблюдать
Better Auth has an Open Redirect Vulnerability in Verify Email Endpoint
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %better-auth · better auth30 дек. 2024 г.
- CVE-2026-5351830Наблюдать
Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %better-auth · better-auth\/oauth-provider15 июл. 2026 г.
- CVE-2026-4533730Наблюдать
Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %better-auth · better auth15 июл. 2026 г.
- CVE-2026-5351430Наблюдать
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %better-auth · better auth15 июл. 2026 г.
- CVE-2026-5351528Наблюдать
Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %better-auth · better-auth\/sso15 июл. 2026 г.
- CVE-2026-4142728Наблюдать
Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clients
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %better-auth · better-auth\/oauth-provider24 апр. 2026 г.
- CVE-2025-2714327Наблюдать
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
СредняяCVSS 6,9Эксплойта нетEPSS 0 %better-auth · better auth24 февр. 2025 г.