CVE-2026-67335
Severity CVSS v4.0:
MEDIUM
Type:
CWE-287
Authentication Issues
Publication date:
01/08/2026
Last modified:
03/08/2026
Description
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attacker's external identity or persistently link attacker accounts to victim profiles.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM



