PT-2026-67308 · Npm · @Better-Auth/Sso
CVE-2026-67328
·
Published
2026-08-01
·
Updated
2026-08-01
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@better-auth/sso versions prior to 1.6.21
Description
Multiple authentication bypass issues exist in the handling of SSO providers, allowing attackers to sign in as arbitrary users. This can be achieved through domain verification parsing mismatches, orphaned provider accounts, or unbound SAML assertions. Additionally, reflected XSS (Cross-Site Scripting, a technique where malicious scripts are injected into trusted websites) on logout endpoints can be used to gain unauthorized session access and account takeover.
Recommendations
Update @better-auth/sso to version 1.6.21 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Better-Auth/Sso