{"id":"CVE-2026-63187","title":"Logto is the modern, open-source auth infrastructure for SaaS and AI apps","summary":"Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's in…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","cwe":["CWE-94"],"published":"2026-08-19","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:15:59.613","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63187","references":[{"url":"https://github.com/logto-io/logto/commit/4a1cab21c14d26d288ffffc509cc2a8cae247b92","label":"security-advisories@github.com"},{"url":"https://github.com/logto-io/logto/pull/9112","label":"security-advisories@github.com"},{"url":"https://github.com/logto-io/logto/releases/tag/v1.41.0","label":"security-advisories@github.com"},{"url":"https://github.com/logto-io/logto/security/advisories/GHSA-869c-8mm3-w5cj","label":"security-advisories@github.com"},{"url":"https://github.com/logto-io/logto/security/advisories/GHSA-869c-8mm3-w5cj","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00361,"epssPercentile":0.29889,"ingestedAt":"2026-09-09T21:22:45.543Z","slug":"CVE-2026-63187","body":"## Overview\n\nLogto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title to npx commitlint. A pull request title containing a single quote could terminate the echo string and append arbitrary shell commands on the GitHub Actions runner. The pull_request trigger used a read-only GITHUB_TOKEN and did not expose repository secrets, but injected commands could alter or disrupt the ephemeral workflow execution. This issue is fixed in version 1.41.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}