Better Auth released v1.6.11 to fix a device authorization vulnerability that could let an authenticated attacker hijack or deny a sign-in if they obtained a valid pending user_code before the legitimate user finished verification. The flaw affected the deviceAuthorization plugin in versions 1.6.0 through 1.6.10 because pending device-code records were not bound to a user during GET /device, and POST /device/approve and POST /device/deny accepted any authenticated session when userId was unset. According to the advisory, exposure could occur through shoulder-surfing, screen sharing, support transcripts, referrer leakage, or shared logs, potentially resulting in account takeover on the polling device or denial of the intended login flow.
The same release also bundled broader security hardening across Better Auth’s authentication stack. Maintainers said they resolved race conditions in magic-link, OAuth authorization-code, and refresh-token flows that could mint multiple sessions or token sets from single-use credentials, and fixed authorization weaknesses involving invitation takeover, improper SSO provider registration permissions, and missing verified-email checks before linking OAuth identities. Additional changes added SSRF protections for user-supplied OIDC endpoints, stricter OAuth 2.1 and confidential-client enforcement, constant-time secret comparison, and safer SCIM token validation, aiming to reduce privilege abuse, token replay, cross-user authorization errors, and insecure federation setups.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub security advisory disclosed that an authenticated attacker who learns a valid pending user_code could hijack or deny a device authorization flow in Better Auth versions 1.6.0 through 1.6.10. The advisory credits the Quikturn Security Team for reporting the issue and describes exposure paths such as screen sharing, support transcripts, and shared logs.
Better Auth fixed a deviceAuthorization plugin flaw affecting versions 1.6.0 through 1.6.10 in release 1.6.11. The fix claims the pending device-code row during GET /device and enforces strict session-to-owner matching on approve and deny actions.
Better Auth merged a fix for an OAuth account-linking flaw that could let an attacker hijack a victim's first OAuth sign-in by pre-registering the victim's email as an unverified local account. The change requires the local account email to already be verified before implicit linking, applies the same protection to the one-tap plugin, and normalizes Google ID-token email_verified values.
Better Auth merged a pull request fixing security issues in the legacy oidc-provider and mcp plugins by requiring confidential clients to authenticate with their client_secret during refresh-token grants. The change also introduced constant-time secret comparisons and removed the wildcard Access-Control-Allow-Origin header from the /mcp/token endpoint.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.