How to use this reference
Editorial reasoning: linking combines authorities, so prove ownership on both sides before merging credentials. Requiring verification only after the merge cannot establish who created the earlier password. Release 1.6.11 corroborates a verified-local-email gate; the advisory also identifies 1.7.0-beta.4 as patched. Disabling implicit linking is a documented interim control.
Before reading
- OAuth identity-provider claims and local account-linking concepts
Context and limits
- Exposure requires email/password sign-in, OAuth or SSO, implicit linking, and an existing unverified local account before the legitimate federated sign-in. Impact is account access, not compromise of the identity provider.
- The advisory lists stable versions below 1.6.11 and 1.7.0-beta.0 through beta.3. Its deprecated compatibility opt-out restores weaker linking behavior.
- gustavovalverde published the advisory; avrmeduard is credited as reporter. Release notes show May 12 without an explicit year in retrieved text; exact patch date is left unestablished.
- Maintainer disclosure, not a peer-reviewed paper, award-backed report, or evidence of production exploitation.
Sources and provenance
- better-auth: OAuth sign-in can link to an account an attacker registered in advance Better Auth · reviewed 2026-10-03
- Release v1.6.11 Better Auth · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.