NPM · JULY 2026 · EARLY WARNING

@better-auth/sso npm Package Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-5RR4-8452-HF4VSeverity: HIGH

An early warning has been issued regarding a potential server-side request forgery vulnerability in the @better-auth/sso npm package, affecting versions >=0.1.0,<1.6.11 or 1.7.0-beta.x.

What happened

The @better-auth/sso npm package is reportedly affected by a server-side request forgery vulnerability due to unvalidated OIDC endpoints. This vulnerability appears to impact versions >=0.1.0,<1.6.11 or 1.7.0-beta.x. The issue is currently under investigation with the tracked ID GHSA-5RR4-8452-HF4V.

Professional software engineers using this package should assess their exposure by checking their dependency versions. It is recommended to upgrade to @better-auth/sso@1.6.11 or later to mitigate the risk. If upgrading is not immediately possible, consult the provided workarounds.

For more detailed information, refer to the primary source: [GHSA-5rr4-8452-hf4v] @better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints (https://github.com/advisories/GHSA-5rr4-8452-hf4v).

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If @better-auth/sso is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats