Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

logto-io — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting logto-io. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data for the vendor logto-io, focusing on software security weaknesses associated with its identity infrastructure products. The collection encompasses a comprehensive range of Common Weakness Enumeration (CWE) classifications, including injection flaws, broken access control, and cryptographic failures, ensuring a holistic view of security posture. This database covers vulnerabilities reported and published within the last five years, capturing both critical severity incidents and lower-risk configuration errors that may impact system integrity. By centralizing this information, the page serves as a vital resource for security researchers, developers, and enterprise administrators who need to monitor the specific threat landscape surrounding logto-io solutions. Users can discover historical trends in the vendor's advisory history, allowing them to track how quickly known issues are addressed over time. Furthermore, it enables the detailed understanding of specific weakness classes prevalent in the ecosystem, such as those related to OAuth 2.0 implementations or session management. The aggregated data also facilitates the lookup of a product's vulnerability history, providing context on repeated security patterns or recurring architectural flaws. This structured approach helps stakeholders prioritize patching efforts and validate compliance with internal security standards without relying on fragmented sources. The content is strictly technical, aiming to provide actionable intelligence for risk mitigation and secure deployment strategies within organizations utilizing logto-io services.

Top products by logto-io: logto
CVE ID Title CVSS Severity Published
CVE-2026-56739 Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint — logto CWE-918 8.5 High 2026-09-24
CVE-2026-63203 Logto: Account API can disclose stored third-party provider tokens without the identities scope — logto CWE-862 7.6 High 2026-09-24
CVE-2026-82263 Logto Server-Side Request Forgery via OIDC SSO Connector Issuer URL — logto CWE-918 6.8 Medium 2026-08-28
CVE-2026-82262 Logto Server-Side Request Forgery via webhook test endpoint — logto CWE-918 6.8 Medium 2026-08-28
CVE-2026-63187 Logto: OS command injection vulnerability exists in the Commitlint workflow — logto CWE-94 6.3 Medium 2026-08-19
CVE-2026-63188 logto-tunnel serves files outside --experience-path via path traversal — logto CWE-22 8.7 High 2026-08-19
CVE-2026-62317 Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing) — logto CWE-1333 7.5 High 2026-08-19
CVE-2026-55377 Logto: Account Center MFA management step-up bypass via WebAuthn registration verification — logto CWE-287 8.1 High 2026-07-10
CVE-2026-55370 Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation) — logto CWE-294 6.4 Medium 2026-07-10
CVE-2026-55789 Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers — logto CWE-91 8.5 High 2026-07-10
CVE-2026-54714 Logto: XSS via unescaped RelayState in SAML auto-submit form — logto CWE-79 6.1 Medium 2026-07-10

This page lists every published CVE security advisory associated with logto-io. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.