logto-io logto是logto-io组织的一个身份认证和用户管理平台。 logto-io logto 1.41.0之前版本存在授权问题漏洞,该漏洞源于TOTP验证使用otplib的无状态检查且未持久化或比较接受的TOTP时间步计数器,导致在RFC 6238接收窗口内可重用已使用的TOTP代码,攻击者在拥有受害者第一因素并捕获实时TOTP值的情况下可重放该值绕过MFA。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55789 | 8.5 HIGH | Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, all |
| CVE-2026-55377 | 8.1 HIGH | Logto: Account Center MFA management step-up bypass via WebAuthn registration verification |
| CVE-2026-54714 | 6.1 MEDIUM | Logto: XSS via unescaped RelayState in SAML auto-submit form |
No comments yet