better-auth@1.0.22 vulnerabilities

The most comprehensive authentication library for TypeScript.

  • latest version

    1.1.8

  • latest non vulnerable version

  • first published

    8 months ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the better-auth package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Open Redirect

    better-auth is a The most comprehensive authentication library for TypeScript.

    Affected versions of this package are vulnerable to Open Redirect via the auth/verify-email endpoint, due to improper validation of callbackURL parameter through the originCheckMiddleware function.

    Note: This vulnerability impacts users relying on email verification links generated by the library.

    How to fix Open Redirect?

    Upgrade better-auth to version 1.1.6 or higher.

    <1.1.6