new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

Better Auth · Concepts · all subjects

api & oauth providers

8 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

OAuth check cookies not bound to issuing provider vulnerability (GHSA-x445-f3h2-j279)

OAuth check cookies were not bound to their issuing provider, allowing potential cross-provider attacks. This is a Medium severity advisory fixed in @auth/core@0.41.3, next-auth@4.24.15, and next-auth@5.0.0-beta.32.

OAuth account linking ownership vulnerability

Advisory GHSA-g38m-r43w-p2q7 addresses a high-severity OAuth account linking ownership issue in better-auth, fixed in better-auth@1.6.11.

OAuth provider client privilege checks vulnerability

Advisory GHSA-xr8f-h2gw-9xh6 (CVE-2026-41427) addresses a high-severity OAuth client privilege checks issue in @better-auth/oauth-provider, fixed in @better-auth/oauth-provider@1.6.5.

OAuth authorization-code redemption vulnerability

Advisory GHSA-7w99-5wm4-3g79 addresses a high-severity OAuth authorization-code redemption issue, fixed in better-auth@1.6.11 and @better-auth/oauth-provider@1.6.11.

OAuth refresh-token rotation vulnerability

Advisory GHSA-392p-2q2v-4372 addresses a high-severity OAuth refresh-token rotation issue in @better-auth/oauth-provider, fixed in @better-auth/oauth-provider@1.6.11.

OAuth resource indicators vulnerability

Advisory GHSA-p2fr-6hmx-4528 addresses a medium-severity OAuth resource indicators issue in @better-auth/oauth-provider, fixed in @better-auth/oauth-provider@1.7.0-beta.4.

SSO provider registration authorization vulnerability

Advisory GHSA-gv74-j8m3-fg5f addresses a high-severity SSO provider registration authorization issue in @better-auth/sso, fixed in @better-auth/sso@1.6.11.

SSO provider registration URL validation vulnerability

Advisory GHSA-5rr4-8452-hf4v addresses a critical-severity SSO provider registration URL validation issue in @better-auth/sso, fixed in @better-auth/sso@1.6.11.

Give your agent this brain