Logto
Logto: vulnerabilidades y CVE
Logto tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses15
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63203 | Alta (7.6) | 0.31% | — | 24 sept 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user… |
| CVE-2026-56739 | Alta (8.5) | 0.30% | — | 24 sept 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used for the connection. Webhook… |
| CVE-2026-82263 | Alta (8.2) | 0.46% | — | 28 ago 2026 | Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API… |
| CVE-2026-82262 | Alta (8.2) | 0.46% | — | 28 ago 2026 | Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens… |
| CVE-2026-63187 | Media (6.3) | 0.39% | — | 19 ago 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on… |
| CVE-2026-62317 | Alta (7.5) | 0.74% | — | 19 ago 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the… |
| CVE-2026-15617 | Crítica (9.1) | 0.43% | — | 23 jul 2026 | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities. |
| CVE-2026-15616 | Crítica (9.1) | 0.53% | — | 23 jul 2026 | Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access. |
| CVE-2026-15615 | Alta (7.5) | 0.19% | — | 23 jul 2026 | Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely. |
| CVE-2026-15614 | Alta (7.5) | 0.35% | — | 23 jul 2026 | Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window. |
| CVE-2026-15612 | Crítica (9.1) | 0.24% | — | 23 jul 2026 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. |
| CVE-2026-15611 | Crítica (9.1) | 0.48% | — | 23 jul 2026 | Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account. |
| CVE-2026-55789 | Alta (8.5) | 0.40% | — | 10 jul 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML application IdP built the signed SAML response and assertion by string-substituting user-controlled… |
| CVE-2026-55377 | Alta (8.1) | 0.46% | — | 10 jul 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up check accepted any active verification record that belonged to the current user and had… |
| CVE-2026-55370 | Media (6.4) | 0.34% | — | 10 jul 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verification accepted a successfully used TOTP code again while the code remained inside the RFC 6238… |