The most comprehensive authentication framework for TypeScript.
92%
Total Score
61
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11093 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Authentication Bypass in versions 1.0.0 - 1.6.12. | 1.0.0 - 1.6.12 | Medium |
AIKIDO-2026-11092 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 1.4.9 - 1.6.11. | 1.4.9 - 1.6.11 | High |
AIKIDO-2026-11094 New better-auth is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 1.6.12. | 0.0.1 - 1.6.12 | Medium |
CVE-2026-45337 New better-auth is vulnerable to Improper Authorization in versions 1.6.0 - 1.6.11. | 1.6.0 - 1.6.11 | High |
CVE-2026-45364 better-auth is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 0.0.0 - 1.4.17 and 1.5.0-beta.1 - 1.5.0-beta.9. | 0.0.0 - 1.4.171.5.0-beta.1 - 1.5.0-beta.9 | High |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.3.6 | — | — |
defu Version ^6.1.4 | — | — |
jose Version ^6.1.3 | — | — |
kysely Version ^0.28.17 || ^0.29.0 | — | — |
nanostores Version ^1.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant