Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hp3-gxv8-7g37

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 5.3

Описание

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles.

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles.

EPSS

Процентиль: 7%
0.00172
Низкий

6 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
nvd
5 дней назад

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles.

EPSS

Процентиль: 7%
0.00172
Низкий

6 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-287