Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

better-auth redirect URI validation bypass enables XSS

better-auth before version 1.6.13 fails to validate redirect URI schemes, allowing attackers to register OAuth clients with javascript: URIs that execute in the authorization server's origin, potentially exposing user sessions and enabling account takeover.

Disclosed 1 August 2026 · Record updated 13 September 2026

Impact

Attackers can execute arbitrary JavaScript in the authorization server's origin, exposing victim sessions and enabling account takeover through maliciously registered OAuth clients.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-67333