OAuth State Validation Bypass in better-auth by Better Auth
CVE-2026-67335
6MEDIUM
What is CVE-2026-67335?
Versions of better-auth prior to 1.6.2 are susceptible to a vulnerability that allows attackers to bypass OAuth state validation. This occurs when cookie-backed state storage is utilized without PKCE, leading to a scenario where the OAuth state parameter is not properly validated against the stored nonce. As a result, attackers can craft a state parameter and provide a malicious authorization code, enabling them to forge authenticated sessions linked to an external identity or to associate attacker-controlled accounts with victim profiles. It is essential for users of the affected versions to update to the latest release to mitigate this significant security risk.
Affected Version(s)
better-auth 0 < 1.6.2
better-auth 1.6.2
