Insecure Cryptographic Defaults in better-auth Product by Better-Auth

⚠️ CVE-Referenzen: CVE-2026-67336
Better-auth - Better-auth - CRITICAL - CVE-2026-67336. Better-auth versions before 1.6.11 exhibit insecure cryptographic defaults within their oidcProvider and mcp plugins. These vulnerabilities arise from the promotion of the 'none' algorithm and the acceptance of plain PKCE by default. Attackers can exploit this misconfiguration, leveraging algorithm negotiation to accept unsigned tokens or to intercept authorization codes when using PKCE in plain format instead of the recommended S256 method. This can potentially undermine the integrity and confidentiality of authentication processes.
Quelle: securityvulnerability.io