Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.36% | — | Better-auth SSOAI | 26/8/2026 | 24/9/2026 | @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Better-authAI | 2/8/2026 | 29/9/2026 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to return 404 for all users (denial of… | |
| Aplazada | Alta (7.1) | 0.35% | — | Better-authAI | 2/8/2026 | 29/9/2026 | better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Rou3AIBetter-auth Better AuthAI | 2/8/2026 | 29/9/2026 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass… | |
| Aplazada | Alta (7.1) | 0.46% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching. | |
| Aplazada | Crítica (9.4) | 0.24% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of… | |
| Aplazada | Media (6) | 0.28% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external… | |
| Aplazada | Media (5.1) | 0.32% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion. | |
| Aplazada | Media (5.1) | 0.26% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the… | |
| Aplazada | Media (5.3) | 0.26% | — | Better-auth Oauth-providerAI | 1/8/2026 | 8/9/2026 | @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never covered, bypassing… | |
| Aplazada | Alta (8.7) | 0.39% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the… | |
| Aplazada | Crítica (9.4) | 0.60% | — | Better-auth ScimAI | 1/8/2026 | 8/9/2026 | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical… | |
| Aplazada | Alta (7.1) | 0.31% | — | Better-auth StripeAI | 1/8/2026 | 8/9/2026 | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the… | |
| Aplazada | Alta (8.6) | 0.49% | — | Better-auth SSOAI | 1/8/2026 | 8/9/2026 | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout… | |
| Aplazada | Alta (8.7) | 0.43% | — | Better-authAI | 1/8/2026 | 8/9/2026 | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address… | |
| Aplazada | Media (5.1) | 0.52% | — | Better-authAI | 1/8/2026 | 29/9/2026 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where the value of the 'error' URL parameter is reflected as HTML without proper neutralization. An attacker who coerces a user into visiting a specially-crafted URL can execute… | |
| Aplazada | Alta (7.1) | 0.34% | — | Better-authAI | 1/8/2026 | 29/9/2026 | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover. | |
| Aplazada | Baja (2) | 0.27% | — | Better-authAI | 1/8/2026 | 29/9/2026 | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-out after-hook, which trusts raw multi-session cookies and forwards extracted values to internalAdapter.deleteSessions without verifying the cookie signature (e.g., via getSignedCookie). An attacker… | |
| Analizada | Alta (7.6) | 0.41% | — | Better-auth/oauth-providerBetter-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete sequence, allowing two concurrent requests to… | |
| Analizada | Alta (8.1) | 0.42% | — | Better-auth/oauth-providerBetter-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests… | |
| Analizada | Alta (8.3) | 0.29% | — | Better-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be… | |
| Analizada | Alta (7.1) | 0.43% | — | Better-auth/ssoBetter-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new SSO provider to that organization because registerSSOProvider checks only for a membership row and does not require an… | |
| Analizada | Alta (7.7) | 0.20% | — | Better-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's acceptInvitation, rejectInvitation, getInvitation,… | |
| Analizada | Crítica (9.6) | 0.25% | — | Better-auth/ssoBetter-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when skipDiscovery: true is set, store them… | |
| Analizada | Crítica (9.1) | 0.27% | — | Better-auth Better Auth | 15/7/2026 | 21/7/2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's… |