{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@better-auth/stripe-1.4.11-1.6.20-1.7.0-beta.0-1.7.0-beta.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-67329"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@better-auth/stripe (1.4.11-1.6.20, 1.7.0-beta.0-1.7.0-beta.9)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","web-vulnerability","billing"],"_cs_type":"advisory","_cs_vendors":["Better Auth"],"content_html":"\u003cp\u003eThe @better-auth/stripe package contains an authorization bypass vulnerability (CVE-2026-67329) affecting versions 1.4.11 through 1.6.20 and specific 1.7.0 beta releases. The vulnerability arises from an inconsistency in how organization IDs are processed. The package middleware performs authorization checks by validating the organization ID provided in the request query string. However, the underlying handler retrieves the target organization ID directly from the request body, or defaults to the session-associated active organization. This discrepancy enables a user who is a member of multiple organizations to bypass authorization controls. By manipulating the request body or session context, a user can execute subscription operations - such as canceling plans, modifying billing, or accessing sensitive payment details - against organizations they are authorized to access as a member, but lack management permissions for. This vulnerability poses a significant risk to multi-tenant SaaS environments using the library for billing integration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated users to access billing details, including payment methods, invoices, and subscription states for organizations they do not manage. Furthermore, attackers can perform unauthorized administrative subscription actions, such as plan changes or account cancellations, resulting in potential service disruption and financial data exposure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade @better-auth/stripe to version 1.6.21 or 1.7.0-beta.10 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview application logs for discrepancies between query parameter organization IDs and the organization IDs processed in request bodies during billing-related API calls.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side validation that enforces a match between the authenticated user's session organization context and the organization identifier in the request body, regardless of query string parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-01T13:54:34Z","date_published":"2026-08-01T13:54:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-stripe-auth-bypass/","summary":"An authorization bypass vulnerability in @better-auth/stripe allows authenticated users to perform unauthorized subscription actions and access billing data of other organizations via ID parameter confusion.","title":"Authorization Bypass in @better-auth/stripe","url":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-stripe-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - @Better-Auth/Stripe (1.4.11-1.6.20, 1.7.0-Beta.0-1.7.0-Beta.9)","version":"https://jsonfeed.org/version/1.1"}