CVE-2026-53512
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refreshtoken grant authenticates only possession of the bound refreshToken row and matching clientid, without verifying the confidential client's clientsecret, allowing an attacker with a valid refreshtoken to mint access tokens and rotated refresh tokens through /api/auth/oauth2/token or /api/auth/mcp/token. The @better-auth/oauth-provider package is not affected. This issue is fixed in version 1.6.11.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/better-auth/better-auth/releases/tag/v1.6.11, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53512.json, https://github.com/better-auth/better-auth/security/advisories/GHSA-pw9m-5jxm-xr6h, https://nvd.nist.gov/vuln/detail/CVE-2026-53512, https://github.com/better-auth/better-auth/commit/1f2ff4215c4affff0b140b0c0a712c0dde35659c, https://github.com/better-auth/better-auth/pull/9576