Intel

AIKIDO-2026-10480

@better-auth/sso is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic Signature Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 15, 2026

72

High Risk

This Affects:

JS@better-auth/sso
1.6.0 - 1.6.2
Fixed in 1.6.3
Are you affected? Scan for Free

TL;DR

The SAML integration could build ACS URLs and provider metadata with inconsistent identifiers, skip database-backed provider resolution when a default SSO config exists, or omit encryption fields needed to decrypt assertions. Callback handling could mis-parse merged configuration, and weak entryPoint validation allowed malformed URLs. Together these defects break correct assertion processing or validation for some IdP configurations. The fix unifies the SAML response pipeline, repairs ACS and encryption handling, tightens URL validation, and rejects unusable IdP configurations up front.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@better-auth/sso is vulnerable to Improper Verification of Cryptographic Signature in versions 1.6.0 - 1.6.2.

How to fix this

Upgrade the @better-auth/sso library to the patch version.