VulnSea

logto vulnerabilities

CVEs whose affected-version data names the logto package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-63203High· 7.6PoC
yesterday

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with …

▾ Midnightlogto-io · logtovia NVD
CVE-2026-56739High· 8.5
yesterday

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used for the connection. Webhook delivery in packages…

▾ Twilightlogto-io · logtovia NVD
CVE-2026-82263Medium· 6.8PoC
4w ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbit…

▾ Twilightlogto-io · logtoEPSS 0.46%via NVD
CVE-2026-82262Medium· 6.8
4w ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server …

▾ Sunlitlogto-io · logtoEPSS 0.46%via NVD
logto vulnerabilities (CVEs) · VulnSea