Logto 是一个面向 SaaS 和 AI 应用现代化、开源的身份验证基础设施。在版本 1.41.0 之前,Logto 在文件 中实现的电子邮件子地址屏蔽黑名单(email subaddressing blocklist)存在安全缺陷:当启用 选项时,该代码使用由用户输入的电子邮件地址中攻击者可控的域名部分来构建 正则表达式。由于配套的 正则表达式设计过于宽松,允许输入中包含多个“@”符号以及正则表达式元字符,攻击者可通过构造特制的恶意电子邮件地址,使程序在处理 接口请求时,在调用 方法过程中引发灾难性回溯(cat
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-63188 | 8.7 HIGH | logto-tunnel serves files outside --experience-path via path traversal |
| CVE-2026-63187 | 6.3 MEDIUM | Logto: OS command injection vulnerability exists in the Commitlint workflow |
No comments yet