Logto 是现代的、开源的身份认证基础设施,适用于 SaaS 和 AI 应用。在版本 0.3.9 之前,Logto Tunnel npm 包存在安全漏洞。具体而言,在 中的 函数处理静态资源请求时,从 获取请求路径,并通过 中的 拼接文件路径,随后使用 打开该文件。此过程未对 URL 进行规范化处理,也未实施路径遍历防护(如目录包含性检查)。 当启用 选项且隧道端口对外可访问时,未经验证的用户可通过构造包含 的路径向 发起请求,从而读取配置静态目录之外、但可被 进程读取的文件。此外,该服务使用 监听端口,根据运行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62317 | 7.5 HIGH | Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing) |
| CVE-2026-63187 | 6.3 MEDIUM | Logto: OS command injection vulnerability exists in the Commitlint workflow |
No comments yet