better-auth redirect URI validation bypass enables XSS
better-auth before version 1.6.13 fails to validate redirect URI schemes, allowing attackers to register OAuth clients with javascript: URIs that execute in the authorization server's origin, potentially exposing user sessions and enabling account takeover.
Disclosed 1 August 2026 · Record updated 13 September 2026
Impact
Attackers can execute arbitrary JavaScript in the authorization server's origin, exposing victim sessions and enabling account takeover through maliciously registered OAuth clients.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-67333
