CVE-2026-67336 PUBLISHED

better-auth before 1.6.11 Insecure Cryptographic Defaults via oidcProvider

Assigner: VulnCheck
Reserved: 29.07.2026 Published: 01.08.2026 Updated: 01.08.2026

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.4

Product Status

Vendor better-auth
Product better-auth
Versions Default: unaffected
  • affected from 0 to 1.6.11 (excl.)
  • Version 1.6.11 is unaffected

Credits

  • subhanUmer reporter

References

Problem Types

  • Use of a Broken or Risky Cryptographic Algorithm CWE