better-auth@1.1.17-beta.4 vulnerabilities

The most comprehensive authentication library for TypeScript.

  • latest version

    1.2.5

  • latest non vulnerable version

  • first published

    11 months ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the better-auth package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Open Redirect

    better-auth is a The most comprehensive authentication library for TypeScript.

    Affected versions of this package are vulnerable to Open Redirect due to insufficient validation of the callbackURL parameter in the trustedOrigins configuration which allows attackers to exploit this vulnerability by crafting specially formatted URLs that bypass the trustedOrigins protection.

    How to fix Open Redirect?

    Upgrade better-auth to version 1.1.21 or higher.

    <1.1.21
    • M
    Open Redirect

    better-auth is a The most comprehensive authentication library for TypeScript.

    Affected versions of this package are vulnerable to Open Redirect due to improper validation of the `callbackURL parameter in the email verification endpoint and other endpoints that accept a callback URL.

    How to fix Open Redirect?

    Upgrade better-auth to version 1.1.20 or higher.

    <1.1.20