Skip to content

Vulnerability in agents project #3156

Description

@ankitdn

While working on agents project, I reviewed the dependency manifest and found that it uses a vulnerable version of @better-auth/oauth-provider. During analysis, I discovered that access control checks for OAuth client creation are not properly enforced. This allows low-privilege authenticated users to create OAuth clients even when restrictions (clientPrivileges) are configured.

CVE Report
CVE Link

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Fields

No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions