@better-auth/scim npm Package: Account Takeover Risk
The @better-auth/scim npm package reportedly has issues with account takeover and stale access due to SCIM provider-id collision. Affected versions are from 1.4.0-beta.27 through 1.6.21 and beta versions from 1.7.0-beta.0 through 1.7.0-beta.9.
What happened
An early warning has been issued regarding potential security issues in the @better-auth/scim npm package. The package appears to have vulnerabilities that could lead to account takeover and stale access due to a SCIM provider-id collision. This issue affects versions from 1.4.0-beta.27 through 1.6.21 and beta versions from 1.7.0-beta.0 through 1.7.0-beta.9. To mitigate these issues, it is recommended to upgrade to version 1.6.22 or 1.7.0-beta.10. The incident is under investigation, and more details can be found in the GitHub Advisory Database under GHSA-rjg6-39jm-rgg4.
Professional software engineers using the @better-auth/scim package should assess their exposure by checking their current version against the affected range. If using a vulnerable version, immediate upgrade to a secure version is advised. Consult the primary sources for the most accurate and up-to-date information on this developing situation.
How 0Day mitigates this
@better-auth/scim is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.