top of page
perceptive_background_267k.jpg

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbit…

Published:

31 July 2026 at 22:00:00

Alert date:

1 August 2026 at 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Supply Chain & Dependencies, Zero-Day Vulnerabilities

The @better-auth/sso npm package versions prior to 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling. Attackers can exploit these flaws to sign in as arbitrary users and perform account takeover. The vulnerabilities include domain verification parsing mismatches, orphaned provider account abuse, unbound SAML assertion exploitation, and reflected XSS on logout endpoints. Each of these attack vectors can independently result in unauthorized session access. The issue affects applications relying on the SSO plugin for authentication delegation. A fix is available in version 1.6.21 and users are strongly advised to upgrade immediately.

Technical details

Mitigation steps:

Affected products:

@better-auth/sso < 1.6.21

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page