new·Earn with mozg — 20% of every monthSend somebody here and take a fifth of every plan payment they make, for as long as they keep paying — not a bounty on the first invoice. Your handle is the link, the window is thirty days, and the commission lands on your balance the second they pay. Free to join: if you have signed in, you already have the link. mozg.sh/earnall news →
mozg.beta
Sign in

Better Auth · Concepts · all subjects

security

18 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Have I Been Pwned API privacy - only first 5 characters of hash sent

When checking if a password is compromised, only the first five characters of the password's SHA-1 hash are sent to the Have I Been Pwned API. The full password is never transmitted.

OIDC and MCP redirect URI validation vulnerability

Advisory GHSA-86j7-9j95-vpqj affects OIDC and MCP redirect URI validation. Severity: High. Fixed in better-auth@1.6.13 and better-auth@1.7.0-beta.4.

OIDC and MCP protocol defaults vulnerability

Advisory GHSA-9h47-pqcx-hjr4 affects OIDC and MCP protocol defaults. Severity: High. Fixed in better-auth@1.6.11.

Current stable Better Auth release

Better Auth 1.6.14 is the current stable release. Stable projects should update to the latest 1.6.x version.

Scoped Better Auth packages must be updated separately

Update any Better Auth packages installed directly, not only the top-level better-auth package. This includes scoped packages such as @better-auth/sso, @better-auth/scim, and @better-auth/oauth-provider.

OAuth account linking ownership vulnerability

Advisory GHSA-g38m-r43w-p2q7 affects OAuth account linking ownership in Core (better-auth). Severity: High. Fixed in better-auth@1.6.11.

Session cleanup after user deletion vulnerability

Advisory GHSA-2vg6-77g8-24mp affects session cleanup after user deletion in Core (better-auth). Severity: Low. Fixed in better-auth@1.6.11 and @better-auth/scim@1.6.11.

Organization invitation ownership vulnerability

Advisory GHSA-fmh4-wcc4-5jm3 affects organization invitation ownership. Severity: High. Fixed in better-auth@1.6.11 with compatibility follow-up in better-auth@1.6.14.

Device-flow owner binding vulnerability

Advisory GHSA-cq3f-vc6p-68fh (CVE-2026-45337) affects device-flow owner binding in Device Authorization. Severity: High. Fixed in better-auth@1.6.11.

OAuth client privilege checks vulnerability

Advisory GHSA-xr8f-h2gw-9xh6 (CVE-2026-41427) affects OAuth client privilege checks in @better-auth/oauth-provider. Severity: High. Fixed in @better-auth/oauth-provider@1.6.5.

OAuth authorization-code redemption vulnerability

Advisory GHSA-7w99-5wm4-3g79 affects OAuth authorization-code redemption. Severity: High. Fixed in better-auth@1.6.11 and @better-auth/oauth-provider@1.6.11.

OAuth refresh-token rotation vulnerability

Advisory GHSA-392p-2q2v-4372 affects OAuth refresh-token rotation in @better-auth/oauth-provider. Severity: High. Fixed in @better-auth/oauth-provider@1.6.11.

OAuth resource indicators vulnerability

Advisory GHSA-p2fr-6hmx-4528 affects OAuth resource indicators in @better-auth/oauth-provider. Severity: Medium. Fixed in @better-auth/oauth-provider@1.7.0-beta.4.

SCIM provider ownership vulnerability

Advisory GHSA-j8v8-g9cx-5qf4 affects SCIM provider ownership in @better-auth/scim. Severity: High. Fixed in @better-auth/scim@1.7.0-beta.4.

SSO provider registration URL validation vulnerability

Advisory GHSA-5rr4-8452-hf4v affects SSO provider registration URL validation in @better-auth/sso. Severity: Critical. Fixed in @better-auth/sso@1.6.11.

SSO provider registration authorization vulnerability

Advisory GHSA-gv74-j8m3-fg5f affects SSO provider registration authorization in @better-auth/sso. Severity: High. Fixed in @better-auth/sso@1.6.11.

OIDC and MCP refresh-token handling vulnerability

Advisory GHSA-pw9m-5jxm-xr6h affects OIDC and MCP refresh-token handling in @better-auth/oauth-provider. Severity: Critical. Fixed in better-auth@1.6.11.

Stable release compatibility approach

Security fixes are deployed to the stable line (1.6.x) when the fix can preserve public types, defaults, and request or response shapes. When fixes require a stronger default or different API contract, they may be shipped through the next package channel or a documented workaround instead.

Give your agent this brain