VulnSea

logto-io has 4 CVEs on record. 4 were published in the last 90 days. The median CVSS is 7.2 (high). The most common weakness class is CWE-918 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
—
Last 90 days
4 prev 0

Weakness classes

Products

  • logto 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

logto-io vulnerabilities

CVEs affecting logto-io, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-63203High· 7.6PoC
today

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with …

▾ Midnightlogto-io · logtovia NVD
CVE-2026-56739High· 8.5
today

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used for the connection. Webhook delivery in packages…

▾ Twilightlogto-io · logtovia NVD
CVE-2026-82263Medium· 6.8PoC
3w ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbit…

▾ Twilightlogto-io · logtoEPSS 0.26%via NVD
CVE-2026-82262Medium· 6.8
3w ago

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server …

▾ Sunlitlogto-io · logtoEPSS 0.26%via NVD
logto-io vulnerabilities (CVEs) · VulnSea