{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/better-auth--1.6.22/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["better-auth \u003c 1.6.22","better-auth 1.7.0-beta \u003c 1.7.0-beta.10"],"_cs_severities":["medium"],"_cs_tags":["account-takeover","vulnerability","web-application","pre-account-hijacking"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eA high-severity pre-account hijacking vulnerability has been identified in the \u003ccode\u003ebetter-auth\u003c/code\u003e library, affecting versions below 1.6.22 and 1.7.0-beta below 1.7.0-beta.10. This flaw enables an attacker to gain and maintain persistent access to a victim's account. The attack targets configurations where the library uses magic-link or email-OTP plugins, alongside open email and password registration, allowing unverified accounts to exist. The core issue lies in the library's failure to remove an attacker-set password or revoke existing sessions when a legitimate user later verifies an account via a passwordless flow that was initially \u0026quot;claimed\u0026quot; by the attacker. This can lead to unauthorized access to personal data, account manipulation, and potential lockout of the legitimate user. The vulnerability is comparable to other pre-account hijacking issues and highlights the importance of authoritative control over email addresses during account verification.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker, leveraging open registration, signs up for an account using the victim's email address and a password of their choice. The account remains unverified at this stage.\u003c/li\u003e\n\u003cli\u003eThe legitimate victim later attempts to sign in or verify their account using a passwordless flow, such as a magic link or an email One-Time Password (OTP).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ebetter-auth\u003c/code\u003e library processes the victim's legitimate passwordless sign-in, marking the pre-existing account as verified and issuing a new session for the victim.\u003c/li\u003e\n\u003cli\u003eDue to the vulnerability, the attacker's pre-set password for the victim's email address is not removed, nor are any existing sessions created by the attacker revoked.\u003c/li\u003e\n\u003cli\u003eThe attacker uses their previously chosen password to log into the victim's now-verified account.\u003c/li\u003e\n\u003cli\u003eThe attacker gains persistent, unauthorized access to the victim's account, potentially reading data, making changes, or initiating a credential reset to lock the victim out.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf successfully exploited, this vulnerability grants an attacker lasting password access to an account that the victim depends on, effectively alongside the legitimate user. This unauthorized access allows the attacker to view, modify, or exfiltrate the victim's data. Furthermore, the attacker could reset the account credentials, leading to a complete lockout of the legitimate account owner. The attack requires a specific configuration of \u003ccode\u003ebetter-auth\u003c/code\u003e that includes open email and password sign-up paired with passwordless flows like magic links or email OTPs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003ebetter-auth\u003c/code\u003e library to version 1.6.22 or later on the stable line, or to version 1.7.0-beta.10 or later on the pre-release line, to patch the vulnerability.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not possible, implement application-level controls to require email verification before accepting any password on an account.\u003c/li\u003e\n\u003cli\u003eImplement application logic to quickly remove unverified accounts to reduce the window of opportunity for pre-account hijacking.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T15:45:24Z","date_published":"2026-07-24T15:45:24Z","id":"https://feed.craftedsignal.io/briefs/2026-07-account-takeover-magic-link-otp/","summary":"An attacker can perform a pre-account hijacking attack against the `better-auth` library if it uses magic-link or email-OTP plugins alongside open email and password registration and allows unverified accounts. The attacker first registers an account using the victim's email with a password they control. When the legitimate victim later uses a passwordless flow to verify their account, the attacker's pre-set password remains active, granting them persistent, unauthorized access to the victim's account and data, potentially leading to account takeover and user lockout.","title":"Account Takeover via Pre-Account Hijacking in Better Auth Library","url":"https://feed.craftedsignal.io/briefs/2026-07-account-takeover-magic-link-otp/"}],"language":"en","title":"CraftedSignal Threat Feed - Better-Auth \u003c 1.6.22","version":"https://jsonfeed.org/version/1.1"}