<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:44:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338109</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338109</link>
      <description>EUVD-2026-338109</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338109</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45337</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45337</link>
      <description>&lt;p&gt;Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker&amp;#39;s account or deny the legitimate flow. This issue is fixed in version 1.6.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of any pending device code because GET /device does not claim the row and POST /device/approve and POST /device/deny short-circuit when userId is unset, allowing an authenticated attacker who learns a valid user_code to bind the polling device to the attacker&amp;#39;s account or deny the legitimate flow. This issue is fixed in version 1.6.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45337</guid>
    </item>
    <item>
      <title>GHSA-cq3f-vc6p-68fh — Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cq3f-vc6p-68fh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: better-auth&lt;/p&gt;
&lt;p&gt;### Am I affected?&lt;/p&gt;
&lt;p&gt;You are affected if all of the following are true:&lt;/p&gt;
&lt;p&gt;- You use `better-auth` at a version `&amp;gt;= 1.6.0, &amp;lt; 1.6.11`.
- The `deviceAuthorization` plugin is enabled in your auth config (`deviceAuthorization()` in your `plugins` array).
- A third party can observe a pending user code before the legitimate user completes verification.&lt;/p&gt;
&lt;p&gt;The standard device-flow UX displays user codes to humans, so realistic exposure includes shoulder-surfing, screen-share, voice or video calls, support-chat transcripts, referrer headers, and shared logs.&lt;/p&gt;
&lt;p&gt;If your application does not enable the `deviceAuthorization` plugin, you are not affected.&lt;/p&gt;
&lt;p&gt;Fix:&lt;/p&gt;
&lt;p&gt;1. Upgrade to `better-auth@1.6.11` or later.
2. If you cannot upgrade, see workarounds below.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Better Auth&amp;#39;s `deviceAuthorization` plugin treated any authenticated session as the owner of any pending device code. The ownership gate on `POST /device/approve` and `POST /device/deny` short-circuited whenever the row&amp;#39;s `userId` was unset, and the `GET /device` verification handler did not claim the row. An authenticated attacker who learned a valid `user_code` before the legitimate user completed approval could bind the polling device to the attacker&amp;#39;s account or deny the legitimate flow.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The device authorization flow binds the polling device to the user who entered the user code on the verification page. In affected versions, the plugin only created that binding at approve or deny time, with no claim at the ver…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: better-auth&lt;/p&gt;
&lt;p&gt;### Am I affected?&lt;/p&gt;
&lt;p&gt;You are affected if all of the following are true:&lt;/p&gt;
&lt;p&gt;- You use `better-auth` at a version `&amp;gt;= 1.6.0, &amp;lt; 1.6.11`.
- The `deviceAuthorization` plugin is enabled in your auth config (`deviceAuthorization()` in your `plugins` array).
- A third party can observe a pending user code before the legitimate user completes verification.&lt;/p&gt;
&lt;p&gt;The standard device-flow UX displays user codes to humans, so realistic exposure includes shoulder-surfing, screen-share, voice or video calls, support-chat transcripts, referrer headers, and shared logs.&lt;/p&gt;
&lt;p&gt;If your application does not enable the `deviceAuthorization` plugin, you are not affected.&lt;/p&gt;
&lt;p&gt;Fix:&lt;/p&gt;
&lt;p&gt;1. Upgrade to `better-auth@1.6.11` or later.
2. If you cannot upgrade, see workarounds below.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Better Auth&amp;#39;s `deviceAuthorization` plugin treated any authenticated session as the owner of any pending device code. The ownership gate on `POST /device/approve` and `POST /device/deny` short-circuited whenever the row&amp;#39;s `userId` was unset, and the `GET /device` verification handler did not claim the row. An authenticated attacker who learned a valid `user_code` before the legitimate user completed approval could bind the polling device to the attacker&amp;#39;s account or deny the legitimate flow.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The device authorization flow binds the polling device to the user who entered the user code on the verification page. In affected versions, the plugin only created that binding at approve or deny time, with no claim at the ver…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cq3f-vc6p-68fh</guid>
    </item>
  </channel>
</rss>
