An oauth provider plugin for Better Auth
94%
Total Score
70
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11111 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @better-auth/oauth-provider is vulnerable to Incorrect Authorization in versions 1.4.8 - 1.6.12. | 1.4.8 - 1.6.12 | High |
AIKIDO-2026-10547 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @better-auth/oauth-provider is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.3.18 - 1.6.5. | 1.3.18 - 1.6.5 | High |
CVE-2026-41427 @better-auth/oauth-provider is vulnerable to Incorrect Authorization in versions 1.4.8-beta.7 - 1.6.5 and 1.7.0-beta.0 - 1.7.0-beta.1. | 1.4.8-beta.7 - 1.6.51.7.0-beta.0 - 1.7.0-beta.1 | High |
AIKIDO-2026-10481 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @better-auth/oauth-provider is vulnerable to Improper Input Validation in versions 1.6.0 - 1.6.2. | 1.6.0 - 1.6.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.3.6 | — | — |
jose Version ^6.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant