@better-auth/sso is vulnerable to Improper Verification of Cryptographic Signature
72
High Risk
The SAML integration could build ACS URLs and provider metadata with inconsistent identifiers, skip database-backed provider resolution when a default SSO config exists, or omit encryption fields needed to decrypt assertions. Callback handling could mis-parse merged configuration, and weak entryPoint validation allowed malformed URLs. Together these defects break correct assertion processing or validation for some IdP configurations. The fix unifies the SAML response pipeline, repairs ACS and encryption handling, tightens URL validation, and rejects unusable IdP configurations up front.
You are affected if you are using a version that falls within the vulnerable range.
@better-auth/sso is vulnerable to Improper Verification of Cryptographic Signature in versions 1.6.0 - 1.6.2.
Upgrade the @better-auth/sso library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant