Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles. | |
| Title | better-auth before 1.6.2 OAuth State Validation Bypass | |
| First Time appeared |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Better-auth
Better-auth better-auth\/oauth-provider |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-01T12:22:17.178Z
Reserved: 2026-07-29T13:07:47.016Z
Link: CVE-2026-67335
No data.
No data.
No data.
OpenCVE Enrichment
No data.