<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:32:53.899306+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338141</id>
    <title>EUVD-2026-338141</title>
    <updated>2026-10-07T18:32:53.954890+00:00</updated>
    <content>EUVD-2026-338141</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53515</id>
    <title>fkie_cve-2026-53515</title>
    <updated>2026-10-07T18:32:53.954934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new SSO provider to that organization because registerSSOProvider checks only for a membership row and does not require an owner or admin role, allowing attacker-controlled OIDC or SAML providers to drive /sso/callback/{providerId} organization provisioning. This issue is fixed in version 1.6.11.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-53515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gv74-j8m3-fg5f</id>
    <title>GHSA-gv74-j8m3-fg5f — @better-auth/sso: SSO provider may allow registration for any org member without a checking their role</title>
    <updated>2026-10-07T18:32:53.954972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @better-auth/sso</p>
<p>### Am I affected?</p>
<p>You are affected if all of the following are true:</p>
<p>- You depend on `@better-auth/sso` at any version in `&gt;= 1.2.10, &lt; 1.6.11`, or any current `next` pre-release.
- You enable both `sso()` and `organization()` plugins.
- `providersLimit` is at its default (`10`) or any non-zero value, so SSO provider registration is enabled for authenticated users.
- An organization has non-admin members, or your application can add users to organizations as regular members.</p>
<p>You are at the highest risk if any of these also hold:</p>
<p>- Organization membership can be obtained without a direct admin decision, such as through open invitations, self-serve onboarding, public team joins, or SCIM bulk imports.
- `organizationProvisioning.defaultRole` or `organizationProvisioning.getRole` returns `admin` or higher for SSO-provisioned users. The bug then becomes unauthorized admin creation in the org.
- `domainVerification.enabled` is `false` (the default). The malicious provider is immediately usable.</p>
<p>Fix:</p>
<p>1. Upgrade to `@better-auth/sso@1.6.11` or later.
2. If you cannot upgrade, see workarounds below.</p>
<p>### Summary</p>
<p>The SSO plugin's `POST /sso/register` endpoint lets any member of an organization attach a new SSO provider to that organization. It checks that the caller has a membership row, but it does not check whether the caller has an administrative role for the organization.</p>
<p>This creates an authorization mismatch for the same resource. Other org-linked SSO provider managemen…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gv74-j8m3-fg5f"/>
  </entry>
</feed>
