<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:54:48 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-338602</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338602</link>
      <description>EUVD-2026-338602</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338602</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53514</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53514</link>
      <description>&lt;p&gt;Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin&amp;#39;s acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invitation ID without sufficient verified-email ownership proof, allowing a user with an unverified session for the invited email address to accept an organization invitation after obtaining the invitation ID. This issue is fixed for the original default behavior in version 1.6.11, while 1.6.14 restored compatibility for built-in opaque invitation IDs and leaves affected configurations requiring secure options.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin&amp;#39;s acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invitation ID without sufficient verified-email ownership proof, allowing a user with an unverified session for the invited email address to accept an organization invitation after obtaining the invitation ID. This issue is fixed for the original default behavior in version 1.6.11, while 1.6.14 restored compatibility for built-in opaque invitation IDs and leaves affected configurations requiring secure options.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53514</guid>
    </item>
    <item>
      <title>GHSA-fmh4-wcc4-5jm3 — Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fmh4-wcc4-5jm3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: better-auth&lt;/p&gt;
&lt;p&gt;### Am I affected?&lt;/p&gt;
&lt;p&gt;Users are affected if all of the following are true:&lt;/p&gt;
&lt;p&gt;- Their application uses `better-auth` with the `organization` plugin (`import { organization } from &amp;#34;better-auth/plugins/organization&amp;#34;`).
- Their application enables a sign-up surface that allows arbitrary unverified email registration. Most commonly `emailAndPassword: { enabled: true }` without `requireEmailVerification: true`.
- Their application has not set `requireEmailVerificationOnInvitation: true` on the `organization()` options.
- Their application invitation distribution flow allows anyone other than the invited mailbox owner to obtain the `invitationId`. Examples: admin UI surfacing the link, copy-paste into chat, forwarded email, mail-forwarding rules at the recipient&amp;#39;s domain, link previews logging the URL, or a custom `sendInvitationEmail` integration that sends to a non-owner channel.&lt;/p&gt;
&lt;p&gt;If their application set `emailAndPassword: { enabled: true, requireEmailVerification: true }` so unverified rows cannot reach a usable session, they are not affected. Setting `requireEmailVerificationOnInvitation: true` closes `acceptInvitation` and `rejectInvitation`, but `getInvitation` and `listUserInvitations` remain ungated even with that flag.&lt;/p&gt;
&lt;p&gt;Fix:&lt;/p&gt;
&lt;p&gt;1. Upgrade to `better-auth@1.6.11` or later.
2. If developers cannot upgrade their application, see workarounds below.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The organization plugin&amp;#39;s `acceptInvitation` endpoint trusts an email-string equality check as proof that the session us…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: better-auth&lt;/p&gt;
&lt;p&gt;### Am I affected?&lt;/p&gt;
&lt;p&gt;Users are affected if all of the following are true:&lt;/p&gt;
&lt;p&gt;- Their application uses `better-auth` with the `organization` plugin (`import { organization } from &amp;#34;better-auth/plugins/organization&amp;#34;`).
- Their application enables a sign-up surface that allows arbitrary unverified email registration. Most commonly `emailAndPassword: { enabled: true }` without `requireEmailVerification: true`.
- Their application has not set `requireEmailVerificationOnInvitation: true` on the `organization()` options.
- Their application invitation distribution flow allows anyone other than the invited mailbox owner to obtain the `invitationId`. Examples: admin UI surfacing the link, copy-paste into chat, forwarded email, mail-forwarding rules at the recipient&amp;#39;s domain, link previews logging the URL, or a custom `sendInvitationEmail` integration that sends to a non-owner channel.&lt;/p&gt;
&lt;p&gt;If their application set `emailAndPassword: { enabled: true, requireEmailVerification: true }` so unverified rows cannot reach a usable session, they are not affected. Setting `requireEmailVerificationOnInvitation: true` closes `acceptInvitation` and `rejectInvitation`, but `getInvitation` and `listUserInvitations` remain ungated even with that flag.&lt;/p&gt;
&lt;p&gt;Fix:&lt;/p&gt;
&lt;p&gt;1. Upgrade to `better-auth@1.6.11` or later.
2. If developers cannot upgrade their application, see workarounds below.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The organization plugin&amp;#39;s `acceptInvitation` endpoint trusts an email-string equality check as proof that the session us…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fmh4-wcc4-5jm3</guid>
    </item>
  </channel>
</rss>
