PT-2026-81905 · Npm · @Better-Auth/Sso
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@better-auth/sso versions prior to 1.4.8
@better-auth/sso versions prior to 1.6.27
@better-auth/sso versions prior to 1.7.0-rc.5
Description
Two domain-ownership flaws exist when the SSO plugin is active. If domain verification is disabled, automatic organization assignment accepts unverified provider domains. This allows an authenticated organization owner or administrator to register an SSO provider for any domain, causing users with matching email domains to be added to the attacker's organization with default member permissions. If domain verification is enabled, a race condition occurs between the 'verify-domain' and 'update-provider' endpoints, which can apply a completed DNS proof to an incorrect domain. When combined with implicit account linking, this allows an attacker-controlled identity provider to be linked to an existing user account. The organization plugin must also be enabled for the organization assignment path to be exploited.
Recommendations
Update @better-auth/sso to version 1.4.8 or later for the 1.4.x line.
Update @better-auth/sso to version 1.6.27 or later.
Update @better-auth/sso to version 1.7.0-rc.5 or later for the 1.7 prerelease line.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Better-Auth/Sso