Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-53513

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when skipDiscovery: true is set, store them on the ssoProvider row without origin validation, and fetch them during OIDC callback, allowing non-blind server-side request forgery and possible account linking when trustEmailVerified: true is configured. This issue is fixed in version 1.6.11.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.6%
CVSS Severity
CVSS v3 Score 9.6
Products affected by CVE-2026-53513


Contact Us

Shodan ® - All rights reserved