Product
The better-auth library fails to validate redirect_uri schemes in its oidc-provider and mcp plugins, allowing attackers to inject javascript: URIs that lead to XSS and potential account takeover.