top of page
perceptive_background_267k.jpg

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plai…

Published:

31 juli 2026 om 22:00:00

Alert date:

1 augustus 2026 om 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies, Supply Chain & Dependencies

better-auth versions prior to 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins. The plugins advertise the 'none' algorithm and accept plain PKCE by default, which are both insecure configurations. Attackers can exploit algorithm negotiation to have systems accept unsigned tokens, bypassing authentication integrity checks. Additionally, when PKCE plain is used instead of the required S256 method, attackers can intercept authorization codes. The vulnerability affects the OAuth/OIDC authentication flow, posing significant identity and access risks. A fix was released in version 1.6.11 of better-auth. The issue has been documented in a GitHub Security Advisory (GHSA-9h47-pqcx-hjr4) and VulnCheck advisories.

Technical details

Mitigation steps:

Affected products:

better-auth

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page