Vulnerabilities/

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

Severity:
High

Description

Users are affected if all of the following are true:

Recommendation

Update the @better-auth/sso package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@better-auth/sso
Anything's wrong? Let us know Last updated on July 20, 2026