A better-auth flaw lets attackers create API keys for arbitrary users, risking account takeover and MFA bypass.
First seen on esecurityplanet.com
Jump to article: www.esecurityplanet.com/threats/better-auth-flaw-allows-unauthenticated-api-key-creation/
![]()

