{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/better-auth-1.7.0-beta.0-through-1.7.0-beta.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-67333"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["better-auth (\u003c 1.6.13)","better-auth (1.7.0-beta.0 through 1.7.0-beta.3)"],"_cs_severities":["high"],"_cs_tags":["xss","oauth","cve-2026-67333"],"_cs_type":"advisory","_cs_vendors":["better-auth"],"content_html":"\u003cp\u003eThe better-auth library, specifically versions prior to 1.6.13 and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3, contains a vulnerability in the oidc-provider and mcp plugins. These plugins fail to validate the scheme of redirect URIs during the registration of OAuth clients. An attacker can supply a malicious redirect URI using the 'javascript:' scheme. When an authorization server returns this URI to a consent page that improperly handles the navigation - typically by assigning the URI directly to window.location.href - the attacker's script executes within the context of the authorization server's origin. This enables the theft of session tokens and full account takeover for affected users. This vulnerability highlights the importance of strictly validating URI schemes before processing navigation in sensitive web application flows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary JavaScript execution in the origin of the authorization server. This facilitates session hijacking and account takeover of authenticated users interacting with the authorization flow. The scope includes any application utilizing the deprecated oidc-provider or mcp plugins within the affected version ranges.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade better-auth to version 1.6.13 or later to remediate CVE-2026-67333.\u003c/li\u003e\n\u003cli\u003eAudit all deployments using the oidc-provider or mcp plugins to ensure redirect URIs are strictly validated against a whitelist of approved schemes (e.g., http, https).\u003c/li\u003e\n\u003cli\u003eReview frontend code responsible for processing OAuth consent pages to ensure navigation logic does not execute values from untrusted user inputs (i.e., avoid dynamic window.location.href assignment with unsanitized URI parameters).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-01T13:54:48Z","date_published":"2026-08-01T13:54:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-redirect-uri-vuln/","summary":"The better-auth library fails to validate redirect_uri schemes in its oidc-provider and mcp plugins, allowing attackers to inject javascript: URIs that lead to XSS and potential account takeover.","title":"Cross-Site Scripting via Improper Redirect URI Validation in better-auth","url":"https://feed.craftedsignal.io/briefs/2026-08-better-auth-redirect-uri-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Better-Auth (1.7.0-Beta.0 Through 1.7.0-Beta.3)","version":"https://jsonfeed.org/version/1.1"}