logto-io has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 7.2 (high). The most common weakness class is CWE-918 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-63203High· 7.6Logto is the modern, open-source auth infrastructure for SaaS and AI apps54CVE-2026-82263Medium· 6.8Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter49CVE-2026-56739High· 8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps47CVE-2026-82262Medium· 6.8Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation37
logto-io vulnerabilities
CVEs affecting logto-io, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-63203High· 7.6PoCLogto is the modern, open-source auth infrastructure for SaaS and AI apps
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with …
CVE-2026-56739High· 8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used for the connection. Webhook delivery in packages…
CVE-2026-82263Medium· 6.8PoCLogto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbit…
CVE-2026-82262Medium· 6.8Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation
Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server …