better-auth — OAuth Refresh-Token Replay
The confidential client secret was never verified during the OAuth refresh-token grant on the oidc-provider and MCP plugins (CWE-306), so a leaked refresh token plus the public client ID could be replayed to mint fresh access and refresh tokens indefinitely. Reported in a 27K-star auth framework with millions of npm downloads; published as CVE-2026-53512 (CVSS 9.1), fix shipped in 1.6.11.