better-auth is vulnerable to Authentication Bypass Using an Alternate Path or Channel
71
High Risk
When two-factor authentication is required on credential sign-in, the library can emit duplicate Set-Cookie headers that still contain valid session_token and session_data values alongside expiring overrides. Anything that reads the raw HTTP response can capture and replay those signed cookies to obtain an authenticated session without completing 2FA when session.cookieCache is enabled, including sensitive two-factor disable flows. The patch scrubs prior matching Set-Cookie entries before expiring cookies and requires a database-backed session for two-factor disable.
You are affected if you are using a version that falls within the vulnerable range.
better-auth is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 1.4.9 - 1.6.11.
Upgrade the better-auth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant