@better-auth/oauth-provider is vulnerable to Incorrect Authorization
71
High Risk
Dynamic client registration at POST /oauth2/register reached OAuth client persistence without running the configured clientPrivileges create gate, while the other client-creation routes enforced it. Deployments that relied on clientPrivileges to restrict who can register clients could still let authenticated users register confidential clients with attacker-chosen redirect URIs and metadata. The fix enforces the create check in the shared createOAuthClientEndpoint chokepoint for every registration path when a session is present.
You are affected if you are using a version that falls within the vulnerable range.
@better-auth/oauth-provider is vulnerable to Incorrect Authorization in versions 1.4.8 - 1.6.12.
Upgrade the @better-auth/oauth-provider library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant