CVE-2026-53512
EUVD-2026-4473515.07.2026, 18:16
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's client_secret, allowing an attacker with a valid refresh_token to mint access tokens and rotated refresh tokens through /api/auth/oauth2/token or /api/auth/mcp/token. The @better-auth/oauth-provider package is not affected. This issue is fixed in version 1.6.11.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| better-auth | better_auth | 𝑥 < 1.6.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration