@better-auth/scim
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @better-auth/scimpage 1 of 1
- CVE-2026-67331HIGHCVSS 8.3EG 8.3✓ Fixed in 1.7.0-beta.42026-08-01
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, …
- CVE-2026-67334LOWCVSS 3.8EG 3.8✓ Fixed in 1.6.112026-08-01
better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session…
Check whether @better-auth/scim is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @better-auth/scim CVEs against the assets you own.
Start Free Scan →