<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T10:22:29.306964+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338602</id>
    <title>EUVD-2026-338602</title>
    <updated>2026-10-07T10:22:29.357984+00:00</updated>
    <content>EUVD-2026-338602</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338602"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53514</id>
    <title>fkie_cve-2026-53514</title>
    <updated>2026-10-07T10:22:29.358029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invitation ID without sufficient verified-email ownership proof, allowing a user with an unverified session for the invited email address to accept an organization invitation after obtaining the invitation ID. This issue is fixed for the original default behavior in version 1.6.11, while 1.6.14 restored compatibility for built-in opaque invitation IDs and leaves affected configurations requiring secure options.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53514"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fmh4-wcc4-5jm3</id>
    <title>GHSA-fmh4-wcc4-5jm3 — Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin</title>
    <updated>2026-10-07T10:22:29.358069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: better-auth</p>
<p>### Am I affected?</p>
<p>Users are affected if all of the following are true:</p>
<p>- Their application uses `better-auth` with the `organization` plugin (`import { organization } from "better-auth/plugins/organization"`).
- Their application enables a sign-up surface that allows arbitrary unverified email registration. Most commonly `emailAndPassword: { enabled: true }` without `requireEmailVerification: true`.
- Their application has not set `requireEmailVerificationOnInvitation: true` on the `organization()` options.
- Their application invitation distribution flow allows anyone other than the invited mailbox owner to obtain the `invitationId`. Examples: admin UI surfacing the link, copy-paste into chat, forwarded email, mail-forwarding rules at the recipient's domain, link previews logging the URL, or a custom `sendInvitationEmail` integration that sends to a non-owner channel.</p>
<p>If their application set `emailAndPassword: { enabled: true, requireEmailVerification: true }` so unverified rows cannot reach a usable session, they are not affected. Setting `requireEmailVerificationOnInvitation: true` closes `acceptInvitation` and `rejectInvitation`, but `getInvitation` and `listUserInvitations` remain ungated even with that flag.</p>
<p>Fix:</p>
<p>1. Upgrade to `better-auth@1.6.11` or later.
2. If developers cannot upgrade their application, see workarounds below.</p>
<p>### Summary</p>
<p>The organization plugin's `acceptInvitation` endpoint trusts an email-string equality check as proof that the session us…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fmh4-wcc4-5jm3"/>
  </entry>
</feed>
