Better Auth 1.7.7 Magic Link Fix, Hono 4.13.13 Update

Executive Summary
- Better Auth 1.7.7 (critical): fixes a Magic Link account-takeover vulnerability (GHSA-965c-763c-88jm), an OAuth Proxy state-validation flaw, and a
disableSignUpbypass on ID-token sign-in. - Hono 4.13.11 (security, Sept 29):
serveStaticdecoded request paths twice, allowing middleware bypass on static paths (GHSA-5r4p-p66f-jhc7). Hono 4.13.13 (today) addshono/mountand deprecatesapp.mount(). - NestJS 12.1.x: logger fixes for JSON output and fatal/buffered logs, MQTT retry logic and better circular-dependency detection; 11.2.7 ships for the v11 line.
- BullMQ 6.3.11: detaches the stalled-job checker from telemetry context to stop a trace leak.
- Prisma 8.0.0 release candidates keep landing daily, with hover docs in
.prismafiles. - Carry-over: if you have not yet patched Next.js, see the September 2026 security release (16.3.8 / 15.5.27).
Better Auth 1.7.7: Magic Link Account Takeover Fixed
The v1.7.7 release (September 30) is the one to act on today. It resolves a critical Magic Link account-takeover vulnerability tracked as GHSA-965c-763c-88jm. No database migration is needed, but deployments where several servers share verification storage must upgrade all of them together.
The same release fixes the OAuth Proxy, which wrongly accepted sign-in state as a provider profile, and enforces a social provider's disableSignUp setting during ID-token sign-in. Rate-limit and CAPTCHA errors now return a JSON Content-Type, and PostgreSQL concurrent rate-limiting and the Kysely adapter's consumeOne were corrected.
npm install [email protected]
# multi-server setups: upgrade every node, then
# request fresh magic links and restart pending OAuth/SAML sign-insIf you use the OAuth Proxy, follow the upgrading existing deployments guide, since all participants must move to the new version at the same time.
Hono: serveStatic Bypass and the New mount Middleware
Hono 4.13.11 fixed GHSA-5r4p-p66f-jhc7: serveStatic decoded the request path a second time, so a crafted request could route as one path and serve another, bypassing middleware guarding static paths. Affected packages include hono/serve-static, hono/bun, hono/deno, hono/cloudflare-workers and the matching @hono/* adapters. The release notes do not state a severity. The fix rejects paths that still contain % after decoding; to serve files with a literal percent sign in the name, opt in with allowPercentInPath: true.
Hono 4.13.13, published today, introduces hono/mount as a handler-based replacement for app.mount(), which stays functional in v4 but is marked for removal in v5. Migration is one line:
import { Router as IttyRouter } from 'itty-router'
import { Hono } from 'hono'
import { mount } from 'hono/mount'
const ittyRouter = IttyRouter()
ittyRouter.get('/hello', () => new Response('Hello from itty-router'))
const app = new Hono()
// before: app.mount('/itty-router', ittyRouter.handle)
app.all('/itty-router/*', mount(ittyRouter.handle))NestJS 12.1.x and 11.2.7
v12.1.1 fixes logger bugs in JSON output, level changes, fatal and buffered logs, hardens microservices (MQTT client retry logic, preserved TCP event listeners) and improves circular-dependency detection and provider overrides. v12.1.2 and v11.2.7 followed on September 30 as maintenance releases with minimal notes.
BullMQ 6.3.11
BullMQ 6.3.11 detaches the stalled-job checker from the telemetry context, preventing a trace leak in workers that run with OpenTelemetry. The Python port also gained getJob in vpy3.3.0.
Prisma 8 Release Candidates
Prisma ORM is still in the 8.0.0 release-candidate series; recent dev builds such as v8.0.0-rc.14-dev.20 add hover declarations and /// doc comments for models, composite types, fields and attributes in .prisma files. These are pre-releases, so keep them out of production.
Registry Snapshot
Latest npm versions as of this morning: Next.js 16.3.8, React 19.3.0, Astro 7.3.5, Svelte 5.57.1, Fastify 5.12.5, Vite 8.3.2, Drizzle ORM 0.45.3, Hono 4.13.13, Better Auth 1.7.7 and BullMQ 6.3.11, per the npm registry. No other release in the audited list carried a security note that we could verify today.
Action Checklist
- Upgrade Better Auth to 1.7.7 on every node that shares verification storage.
- Upgrade Hono to 4.13.11 or later wherever
serveStaticguards content with middleware. - Plan the
app.mount()tomount()migration before Hono v5. - Confirm Next.js is on 16.3.8 or 15.5.27.
Comments
Share your thoughts and join the conversation



