@better-auth/sso is vulnerable to Improper Verification of Cryptographic Signature
30
Low Risk
Affected versions of this package are vulnerable to SAML signature validation bypass due to fallback parsing and response patching that accepted unsigned or forged assertions, where attackers could exploit this by crafting malicious SAML responses without valid signatures to gain unauthorized access, as the vulnerability stemmed from regex-based NameID extraction and status success patching in callbackSSOSAML and ACS endpoints that bypassed strict signature checks.
You are affected if you are using a version that falls within the vulnerable range.
@better-auth/sso is vulnerable to Improper Verification of Cryptographic Signature in versions 1.4.0 - 1.4.6.
Upgrade the @better-auth/sso library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant