Insecure Cryptographic Defaults in better-auth Product by Better-Auth
CVE-2026-67336
9.4CRITICAL
What is CVE-2026-67336?
Better-auth versions before 1.6.11 exhibit insecure cryptographic defaults within their oidcProvider and mcp plugins. These vulnerabilities arise from the promotion of the 'none' algorithm and the acceptance of plain PKCE by default. Attackers can exploit this misconfiguration, leveraging algorithm negotiation to accept unsigned tokens or to intercept authorization codes when using PKCE in plain format instead of the recommended S256 method. This can potentially undermine the integrity and confidentiality of authentication processes.
Affected Version(s)
better-auth 0 < 1.6.11
better-auth 1.6.11
