PT-2026-67308 · Npm · @Better-Auth/Sso

CVE-2026-67328

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @better-auth/sso versions prior to 1.6.21
Description Multiple authentication bypass issues exist in the handling of SSO providers, allowing attackers to sign in as arbitrary users. This can be achieved through domain verification parsing mismatches, orphaned provider accounts, or unbound SAML assertions. Additionally, reflected XSS (Cross-Site Scripting, a technique where malicious scripts are injected into trusted websites) on logout endpoints can be used to gain unauthorized session access and account takeover.
Recommendations Update @better-auth/sso to version 1.6.21 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67328
GHSA-PRPR-5GJ3-QQHG

Affected Products

@Better-Auth/Sso