Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xr8f-h2gw-9xh6 | OAuth 2.1 Provider: Unprivileged users can register OAuth clients |
Wed, 13 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Better-auth better-auth\/oauth-provider
|
|
| CPEs | cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:* cpe:2.3:a:better-auth:better-auth\/oauth-provider:1.4.8:-:*:*:*:node.js:*:* cpe:2.3:a:better-auth:better-auth\/oauth-provider:1.4.8:beta7:*:*:*:node.js:*:* cpe:2.3:a:better-auth:better-auth\/oauth-provider:1.7.0:beta0:*:*:*:node.js:*:* |
|
| Vendors & Products |
Better-auth better-auth\/oauth-provider
|
|
| Metrics |
cvssV3_1
|
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Better-auth
Better-auth better Auth Better-auth oauth-provider |
|
| Vendors & Products |
Better-auth
Better-auth better Auth Better-auth oauth-provider |
Mon, 27 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation endpoints did not invoke the hook before persisting new clients. Deployments that configured clientPrivileges to restrict client registration were not actually restricted — any authenticated user could reach the create endpoints and register an OAuth client with attacker-chosen redirect URIs and metadata. This vulnerability is fixed in 1.6.5. | |
| Title | Better Auth OAuth 2.1 Provider: Unprivileged users can register OAuth clients | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-27T13:42:23.885Z
Reserved: 2026-04-20T15:32:33.814Z
Link: CVE-2026-41427
Updated: 2026-04-27T13:42:19.429Z
Status : Analyzed
Published: 2026-04-24T20:16:27.390
Modified: 2026-05-13T19:36:38.053
Link: CVE-2026-41427
No data.
OpenCVE Enrichment
Updated: 2026-04-28T13:45:06Z
Github GHSA