CVE-2026-53513Better-auth · Better-auth\/sso
Vulnerability data via NVD (ingested)
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when skipDiscovery: true is set, store them on the ssoProvider row without origin validation, and fetch them during OIDC callback, allowing non-blind server-side request forgery and possible account linking when trustEmailVerified: true is configured. This issue is fixed in version 1.6.11.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-53513product:"Better-auth Better-auth\/sso"http.html:"Better-auth\/sso"More intel sources (5)
vuln:CVE-2026-53513vulnerabilities.cve_id: CVE-2026-53513CVE-2026-53513CVE-2026-53513"CVE-2026-53513" exploit -site:nvd.nist.gov