Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.31% | — | LogtoAI | 24/9/2026 | 24/9/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scope to retrieve stored social or enterprise SSO provider access… | |
| Aplazada | Alta (8.5) | 0.30% | — | LogtoAI | 24/9/2026 | 28/9/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used for the connection. Webhook delivery in packages/core/src/libraries/hook/utils.ts can reach special-use and cloud metadata… | |
| Aplazada | Alta (8.2) | 0.46% | — | LogtoAI | 28/8/2026 | 8/9/2026 | Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET requests to private network services, with… | |
| Aplazada | Alta (8.2) | 0.46% | — | LogtoAI | 28/8/2026 | 8/9/2026 | Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs and retrieve response bodies from… | |
| Aplazada | Alta (8.7) | 0.54% | — | Logto TunnelAI | 19/8/2026 | 9/9/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static asset requests through packages/tunnel/src/commands/tunnel/utils.ts using… | |
| Aplazada | Media (6.3) | 0.39% | — | LogtoAI | 19/8/2026 | 9/9/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title to npx commitlint. A pull request title… | |
| Aplazada | Alta (7.5) | 0.74% | — | LogtoAI | 19/8/2026 | 9/9/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain from email input to construct subaddressingRegex when blockSubaddressing was… | |
| Aplazada | Crítica (9.1) | 0.43% | — | LogtoAI | 23/7/2026 | 27/7/2026 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. | |
| Aplazada | Crítica (9.1) | 0.53% | — | LogtoAI | 23/7/2026 | 27/7/2026 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. | |
| Aplazada | Alta (7.5) | 0.19% | — | LogtoAI | 23/7/2026 | 27/7/2026 | Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely. | |
| Aplazada | Alta (7.5) | 0.35% | — | LogtoAI | 23/7/2026 | 27/7/2026 | Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window. | |
| Aplazada | Crítica (9.1) | 0.24% | — | LogtoAI | 23/7/2026 | 27/7/2026 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. | |
| Aplazada | Crítica (9.1) | 0.48% | — | LogtoAI | 23/7/2026 | 27/7/2026 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. | |
| Aplazada | Alta (8.5) | 0.40% | — | LogtoAISamlifyAI | 10/7/2026 | 13/7/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled profile attributes such as name, email, and custom attribute-mapping values into element-text… | |
| Aplazada | Alta (8.1) | 0.46% | — | LogtoAI | 10/7/2026 | 13/7/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had isVerified === true. A WebAuthn registration verification record for binding a new passkey could be created… | |
| Aplazada | Media (6.4) | 0.34% | — | LogtoAI | 10/7/2026 | 13/7/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verification accepted a successfully used TOTP code again while the code remained inside the RFC 6238 acceptance window because the verifier used otplib's stateless check with window = 1 and did not… | |
| Aplazada | Media (6.1) | 0.34% | — | Logto CoreAI | 10/7/2026 | 13/7/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML RelayState, SAMLResponse, and actionUrl into a Logto-origin auto-submit HTML form in packages/core/src/saml-application/SamlApplication/utils.ts without HTML-attribute escaping. A SAML application… |