VYPR

oauth-provider

by @better Auth

CVEs (1)

  • CVE-2026-67332Aug 1, 2026
    risk 0.00cvss epss 0.00

    @better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the…