Signal is active with 1 mentions in latest observed window
Immediate actions
Patch better-auth better-auth\/sso systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST /sso/update-provider endpoints accept attacker-controlled oidcConfig.userInfoEndpoint, tokenEndpoint, and jwksEndpoint URLs when skipDiscovery: true is set, store them on the ssoProvider row without origin validation, and fetch them during OIDC callback, allowing non-blind server-side request forgery and possible account linking when trustEmailVerified: true is configured. This issue is fixed in version 1.6.11.
CVE-2026-53513 is a Better Auth SSRF flaw (CVSS 9.6) in the SSO plugin. It exposes cloud metadata and enables account takeover. Patch to 1.6.11 now.
#BetterAuth#SSRF#CVE202653513#SSO#OIDC
http://securityonline.info/better-auth-ssrf-cve-2026-53513/
Post summary
CVE‑2026‑53513 is a high‑severity SSRF flaw in the Better Auth SSO plugin that exposes cloud metadata and permits account takeover; the patch 1.6.11 is now available.
🚨 CRITICAL - Unvalidated OIDC endpoints allow SSRF in provider registration (CVE-2026-53513)
CVE-2026-53513 is an SSRF flaw in the @better-auth/sso provider registration flow where OpenID Connect (OIDC) endpoint URLs are accepted without proper validation/verification. The root cause is improper input validation and insufficient trust checking of attacker-controlled endpoint metadata. An attacker can register or supply a malicious OIDC configuration to coerce the server into making outbound HTTP requests to arbitrary targets, including internal network addresses, with no special privileges beyond access to the registration/config path. Successful exploitation can enable internal network probing, access to cloud metadata services, and downstream data exposure that may lead to broader compromise.
👉 Affected: @better-auth/sso < 1.6.11 | Upgrade to 1.6.11
Post summary
The text announces a critical SSRF flaw (CVE-2026-53513) in the @better-auth/sso provider registration flow, details the vulnerability and its impact, and advises upgrading to version 1.6.11.