@better-auth/sso npm Package Vulnerability: Early Warning
An early warning has been issued regarding a potential server-side request forgery vulnerability in the @better-auth/sso npm package, affecting versions >=0.1.0,<1.6.11 or 1.7.0-beta.x.
What happened
The @better-auth/sso npm package is reportedly affected by a server-side request forgery vulnerability due to unvalidated OIDC endpoints. This vulnerability appears to impact versions >=0.1.0,<1.6.11 or 1.7.0-beta.x. The issue is currently under investigation with the tracked ID GHSA-5RR4-8452-HF4V.
Professional software engineers using this package should assess their exposure by checking their dependency versions. It is recommended to upgrade to @better-auth/sso@1.6.11 or later to mitigate the risk. If upgrading is not immediately possible, consult the provided workarounds.
For more detailed information, refer to the primary source: [GHSA-5rr4-8452-hf4v] @better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints (https://github.com/advisories/GHSA-5rr4-8452-hf4v).
How 0Day mitigates this
@better-auth/sso is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.