Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Better Auth SSRF Flaw CVE-2026-53513 (CVSS 9.6) Threatens 19M-Download Auth Library
  • Vulnerability Report

Better Auth SSRF Flaw CVE-2026-53513 (CVSS 9.6) Threatens 19M-Download Auth Library

Do Son July 14, 2026 2 minutes read
0
Better Auth SSRF vulnerability CVE-2026-53513 in the SSO plugin exposing OIDC provider registration
Add Daily CyberSecurity as a preferred source on Google
At a glance
  • CVE: CVE-2026-53513
  • CVSS: 9.6 (Critical Β· CVSSv3)
  • Product: better-auth
  • Affected: >= 0.1.0, < 1.6.11
  • Impact: Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
  • Status: No confirmed exploitation yet
  • EPSS: 0.2% (30-day)
  • Action: See vendor advisory

Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.

Try Team free for 14 days →

TL;DR

A critical Better Auth SSRF flaw, tracked as CVE-2026-53513, lets any logged-in user reach internal services. The bug carries a CVSS score of 9.6 and sits in the @better-auth/sso plugin. Maintainers fixed it in version 1.6.11, so upgrade quickly.

Why It Matters

Better Auth is a popular authentication framework for TypeScript. The core npm package draws more than 19 million downloads each month, according to project figures. Therefore, this Better Auth SSRF flaw reaches a wide base of production apps.

The impact runs deep. An attacker with a normal session can read responses from internal endpoints. That includes cloud metadata services like AWS IMDS, plus Redis or admin panels bound to localhost.

How the Attack Works

The flaw lives in the plugin’s provider registration flow. When a developer sets skipDiscovery: true, the POST /sso/register endpoint accepts attacker-supplied OIDC endpoint URLs. Crucially, it stores them without checking their origin.

Later, during the OIDC callback, the server fetches those URLs. It then reflects the response body through the user profile. As a result, the attacker reads internal data directly, which makes this a non-blind SSRF. The same weakness affects POST /sso/update-provider.

Escalation to Account Takeover

Things get worse with one setting. When trustEmailVerified: true is active, a crafted userInfo response can assert a verified email. That triggers OAuth auto-linking against an existing account, which escalates the bug into account takeover.

Affected Versions

The issue affects @better-auth/sso from 0.1.0 up to (but not including) 1.6.11. Any 1.7.0-beta.x release on the pre-release line is also vulnerable. You are exposed only if the sso() plugin sits in your betterAuth plugins array.

By contrast, deployments without the SSO plugin stay safe. No public proof-of-concept or in-the-wild exploitation has been confirmed so far.

Patch and Mitigation Steps

First, upgrade to @better-auth/sso 1.6.11 or later. You can track the fix on the official Better Auth releases page. The patch validates every OIDC endpoint URL and rejects private, loopback, and cloud-metadata targets.

If you cannot patch yet, several workarounds help. Set sso({ providersLimit: 0 }) to block self-registration outright. Alternatively, gate /sso/register at your reverse proxy, and set trustEmailVerified: false to drop the takeover path.

For full technical detail, read the official GitHub security advisory. Above all, patch soon, because this Better Auth SSRF bug hands attackers a direct line into your infrastructure.

Related coverage

  • Kiteworks Patches 78 Vulnerabilities, Including Critical Account Takeover Flaw
  • Dropbox Lenovo ID Flaw Let Attackers Hijack Accounts by Email
  • ManageEngine Account Takeover Flaw CVE-2026-11374
  • CISA Alert: MongoBleed Added to KEV Catalog as 80,000+ Servers Face Active Exploitation
  • BlueHammer: Researcher Drops Functional 0-Day Exploit Targeting Windows Defender
  • GeoServer Cloud Fixes CVSS 10 GitHub Actions Flaw That Exposed Repository Secrets
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS Β· Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover Better Auth CVE-2026-53513 OIDC SSO ssrf TypeScript Authentication

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
πŸ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

πŸ›‘οΈ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

πŸ™

GitHub Issues
Auto-create alert tickets without duplication.

πŸ“¬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

πŸ”€

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days β†’

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-59346CVSS 9.3
    VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual...
    📅 Updated: Oct 7, 2026
  • CVE-2025-52691CVSS 10.0
    Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on...
    CISA KEV📅 Added to KEV: Jan 26, 2026📅 Updated: Oct 7, 2026
  • CVE-2025-57460CVSS 9.8
    File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
    📅 Updated: Oct 7, 2026
  • CVE-2025-68897CVSS 9.9
    Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows...
    📅 Updated: Oct 7, 2026
  • CVE-2025-68562CVSS 9.9
    Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a...
    📅 Updated: Oct 7, 2026
  • CVE-2025-69234CVSS 9.1
    Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
    📅 Updated: Oct 7, 2026
  • CVE-2025-15102CVSS 9.1
    DVP-12SE11T - Password Protection Bypass
    📅 Updated: Oct 7, 2026
  • CVE-2025-15359CVSS 9.1
    DVP-12SE11T - Out-of-bound memory write Vulnerability
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.