The most comprehensive authentication framework for TypeScript.
92%
Total Score
60
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10479 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Insufficient Authentication in versions 0.0.1 - 1.6.2. | 0.0.1 - 1.6.2 | High |
AIKIDO-2026-10482 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Incorrect Authorization in versions 1.4.0 - 1.6.2. | 1.4.0 - 1.6.2 | Low |
AIKIDO-2026-10485 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.2.0 - 1.6.2. | 1.2.0 - 1.6.2 | High |
AIKIDO-2026-10373 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to Open Redirect in versions 1.0.0 - 1.5.4. | 1.0.0 - 1.5.4 | Medium |
AIKIDO-2025-10908 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. better-auth is vulnerable to External Control of File Name or Path in versions 0.0.1 - 1.4.2. | 0.0.1 - 1.4.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^4.3.6 | — | — |
defu Version ^6.1.4 | — | — |
jose Version ^6.1.3 | — | — |
kysely Version ^0.28.14 | — | — |
nanostores Version ^1.1.1 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant