Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch better-auth better_auth systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's client_secret, allowing an attacker with a valid refresh_token to mint access tokens and rotated refresh tokens through /api/auth/oauth2/token or /api/auth/mcp/token. The @better-auth/oauth-provider package is not affected. This issue is fixed in version 1.6.11.
🚨 CRITICAL - OAuth refresh_token client authentication bypass in better-auth OIDC/MCP plugins (CVE-2026-53512)
In better-auth’s legacy oidcProvider and mcp plugins, the OAuth 2.0 token endpoint fails to authenticate confidential clients during the refresh_token grant, allowing token refresh without validating the client_secret. The root cause is improper authentication / missing secret verification (broken client authentication) combined with flawed Basic auth parsing and overly permissive CORS on the mcp token endpoint. An attacker who obtains a valid refresh_token and knows the public client_id can hit the token endpoint and repeatedly mint fresh access tokens and rotated refresh tokens until the token is revoked. Impact includes sustained unauthorized API access and session persistence, enabling account takeover-style access, data exposure, and long-lived compromise via continuous token renewal.
👉 Affected: better-auth legacy oidcProvider and mcp plugins < 1.6.11 | Upgrade to 1.6.11
Post summary
The post discloses CVE-2026-53512, explains an OAuth refresh_token authentication bypass, details its impact, and advises upgrading to version 1.6.11.