Back to search

CVE-2026-67333

HIGH
7.2NVD

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the authorization server later returns unchanged in the consent response. If the deployment's consent page navigates the browser to the returned redirectURI (e.g. assigning it to window.location.href), the attacker's JavaScript executes in the authorization-server origin, exposing the victim's session and enabling account takeover.

Share:

CVSS v3.1 Score

7.2
/ 10.0
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Information

Published
1 août 2026
Updated
1 août 2026
Status
Received
Source
disclosure@vulncheck.com

Weaknesses (CWE)

CWE-79

Similar CVEs

Other vulnerabilities of type CWE-79

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring