CVE-2026-53514
Description
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invitation ID without sufficient verified-email ownership proof, allowing a user with an unverified session for the invited email address to accept an organization invitation after obtaining the invitation ID. This issue is fixed for the original default behavior in version 1.6.11, while 1.6.14 restored compatibility for built-in opaque invitation IDs and leaves affected configurations requiring secure options.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
better-authnpm | < 1.6.11 | 1.6.11 |
Affected products
2cpe:2.3:a:better-auth:better_auth:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:better-auth:better_auth:*:*:*:*:*:node.js:*:*range: <1.6.11
- (no CPE)range: <1.6.11, >=1.6.14
Patches
Vulnerability mechanics
References
6- github.com/better-auth/better-auth/commit/23094a628f007f801be6d26e5b15dc5fc6fc4eb8nvdPatchWEB
- github.com/better-auth/better-auth/pull/9577nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-fmh4-wcc4-5jm3ghsaADVISORY
- github.com/better-auth/better-auth/security/advisories/GHSA-fmh4-wcc4-5jm3nvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-53514ghsaADVISORY
- github.com/better-auth/better-auth/releases/tag/v1.6.11nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.