Impact
The vulnerability in better‑auth allows an attacker to hijack an account by registering the victim’s e‑mail and a chosen password. When the legitimate user later signs in using magic‑link or email‑OTP, the account is marked verified but the attacker’s password remains valid, giving the attacker persistent access. This bypasses authentication and is described as CWE‑287.
Affected Systems
The affected product is better‑auth OAuth Provider for Node.js. All released versions from 1.1.3 up to, but not including, 1.6.22 and the pre‑release <1.7.0‑beta.10 are vulnerable. These versions expose a pre‑account creation path when open e‑mail/password registration is enabled.
Risk and Exploitability
The CVSS score is 8.7, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs the victim’s e‑mail address and the ability to submit a registration request; no privileged access is required. Because the attack path is part of the normal sign‑in flow, it can be exploited remotely with minimal effort, making it a high‑risk exposure until mitigated.
OpenCVE Enrichment