CVE-2026-67333Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-01); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-08-01: 2Mentions · 2026-08-02: 1Mentions · 2026-08-03: 2Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-01: 2Technical Details · 2026-08-02: 1Technical Details · 2026-08-03: 108-0108-0208-03
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-012
Disclosure1General1
2026-08-021
Disclosure1
2026-08-032
General1Patch1
Full discourse5 posts
  • Mohi@disismohi
    General

    CVE-2026-67333: better-auth shipped the OAuth redirect vulnerability from every security training deck. Here's what actually breaks and how to check your own code.

    Post summary

    The post references CVE‑2026‑67333 as an OAuth redirect vulnerability but provides no further technical detail, exploit code, patch information, or evidence of active exploitation.

    1000072
    73 followersView on X
  • Mohi@disismohi
    Patch

    javascript: URIs in OAuth redirect_uri are never legitimate. If your validation logic doesn't reject them, patch that before the next client registers. source: https://nvd.nist.gov/vuln/detail/CVE-2026-67333

    Post summary

    The note highlights a vulnerability in OAuth redirect_uri handling and urges applying a patch before new clients are registered, without providing PoC or exploit details.

    0000038
    73 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-67333 - High sev URL scheme bypass in Better-Auth. javascript: redirect_uri allows XSS on consent pages. CVSS 7.2. No patch yet, block untrusted clients now. #CVE #BetterAuth #infosec #devsecops #cybersecuritytips #cybersecuritynews #python #git #github #gitlab #redteam #blueteam #hacker #hackers #kali #linux #ubuntu #debian https://www.valtersit.com/cve/CVE-2026-67333/

    Post summary

    The post announces a high‑severity URL scheme bypass in Better‑Auth that enables XSS on consent pages; no patch exists yet, so users are advised to block untrusted clients.

    0000070
    979 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-67333 better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-p… https://www.cve.org/CVERecord?id=CVE-2026-67333 ----- Traducción: CVE-2026-67333 bet… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-67333 and describes a redirect_uri scheme validation flaw in better-auth, links to the CVE record, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000035
    96 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-67333 better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-p… https://www.cve.org/CVERecord?id=CVE-2026-67333

    Post summary

    The excerpt indicates that earlier releases of better‑auth suffer from a redirect‑URI scheme validation flaw that could potentially be abused, but no exploitation details, fixes, or PoC were provided.

    000001.0K
    57.9K followersView on X

Explore more