Skip to content
The Auth.js project is now part of Better Auth.

Supported versions

  • Security updates are only released for the current latest version.
  • Old releases are not maintained and do not receive updates.
💡

@auth/* packages (other than the database adapters) are currently under development and - unless stated otherwise - they are not considered ready for production yet. That said, we encourage you to reach out to us if you have any questions or concerns via the below-mentioned channels. We are committed to making Auth.js a secure and reliable solution for your authentication needs.

Reporting a Vulnerability

Auth.js practices responsible disclosure. We request that you contact us directly to report serious issues that might impact the security of sites using Auth.js. Please do not disclose the vulnerability publicly until it has been addressed by our team.

Email your findings to security@better-auth.com and include:

  • The repository the vulnerability comes from (in this case NextAuth)
  • A description of the vulnerability
  • Steps to reproduce the vulnerability
  • The potential impact of the vulnerability
  • Any suggestions for mitigation
  • Any other relevant information

Getting back to you

We will respond to your report within 72 hours.

Publishing a fix

If the issue is confirmed, we will release a patch as soon as possible.

Disclosing the issue

Once a patch is released, we will disclose the issue publicly ( and credit you, with your consent ).

90 days limit

If 90 days have elapsed and we still don’t have a fix, we will disclose the issue publicly.

For less serious issues (e.g. RFC compliance for unsupported flows or potential issues that may cause a problem in the future) it is appropriate to make these public as bug reports or feature requests or to raise a question to open a discussion around them.

Auth.js © Better Auth Inc. - 2026