<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T19:45:48.943875+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338109</id>
    <title>EUVD-2026-338109</title>
    <updated>2026-10-08T19:45:49.000609+00:00</updated>
    <content>EUVD-2026-338109</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338109"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45337</id>
    <title>fkie_cve-2026-45337</title>
    <updated>2026-10-08T19:45:49.000649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker's account or deny the legitimate flow. This issue is fixed in version 1.6.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cq3f-vc6p-68fh</id>
    <title>GHSA-cq3f-vc6p-68fh — Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending</title>
    <updated>2026-10-08T19:45:49.000685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: better-auth</p>
<p>### Am I affected?</p>
<p>You are affected if all of the following are true:</p>
<p>- You use `better-auth` at a version `&gt;= 1.6.0, &lt; 1.6.11`.
- The `deviceAuthorization` plugin is enabled in your auth config (`deviceAuthorization()` in your `plugins` array).
- A third party can observe a pending user code before the legitimate user completes verification.</p>
<p>The standard device-flow UX displays user codes to humans, so realistic exposure includes shoulder-surfing, screen-share, voice or video calls, support-chat transcripts, referrer headers, and shared logs.</p>
<p>If your application does not enable the `deviceAuthorization` plugin, you are not affected.</p>
<p>Fix:</p>
<p>1. Upgrade to `better-auth@1.6.11` or later.
2. If you cannot upgrade, see workarounds below.</p>
<p>### Summary</p>
<p>Better Auth's `deviceAuthorization` plugin treated any authenticated session as the owner of any pending device code. The ownership gate on `POST /device/approve` and `POST /device/deny` short-circuited whenever the row's `userId` was unset, and the `GET /device` verification handler did not claim the row. An authenticated attacker who learned a valid `user_code` before the legitimate user completed approval could bind the polling device to the attacker's account or deny the legitimate flow.</p>
<p>### Details</p>
<p>The device authorization flow binds the polling device to the user who entered the user code on the verification page. In affected versions, the plugin only created that binding at approve or deny time, with no claim at the ver…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cq3f-vc6p-68fh"/>
  </entry>
</feed>
