PatchSiren

logto-io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH logto-io CVE published 2026-09-24

CVE-2026-56739

CVE-2026-56739 is a high-severity vulnerability in Logto, an open-source authentication infrastructure for SaaS and AI applications. Prior to version 1.43.0, Logto's webhook delivery and custom OAuth2 and OIDC connectors can be exploited to reach special-use and cloud metadata addresses, potentially exposing internal data or upstream provider credentials. This issue requires tenant administrative configur [truncated]

HIGH logto-io CVE published 2026-08-28

CVE-2026-82263

CVE-2026-82263 is a high-severity vulnerability in Logto, a software identity and access management solution. The vulnerability is caused by a server-side request forgery (SSRF) issue in the OIDC SSO connector creation endpoint, which allows tenant administrators with Management API credentials to supply arbitrary internal URLs and trigger HTTP GET requests to private network services. The response conten [truncated]

HIGH logto-io CVE published 2026-08-28

CVE-2026-82262

CVE-2026-82262 is a server-side request forgery vulnerability in Logto through version 1.42.0. The vulnerability exists in the POST /api/hooks/:id/test endpoint, which accepts arbitrary URLs without host validation. This allows tenant administrators with Management API tokens to make the server issue HTTP POST requests to internal URLs and retrieve response bodies from services on the private network.

HIGH logto-io CVE published 2026-08-19

CVE-2026-62317

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-62317 was published on 2026-08-19T20:17:19.890Z and has not been modified since then. The NVD entry is currently 7.5 HIGH. The vulnerability affects Logto, an open-source auth infrastructure for SaaS and AI apps, specifically its email subaddressing blocklist feature in packages/core/src/libraries/sign-in-exper [truncated]

HIGH logto-io CVE published 2026-07-10

CVE-2026-55789

CVE-2026-55789 is a high-severity vulnerability in Logto's self-hosted SAML application IdP. Prior to version 1.41.0, an authenticated low-privilege user could inject XML markup into profile attributes, allowing the creation of forged SAML attributes, such as arbitrary roles, and potentially leading to privilege escalation at relying Service Providers that authorize on SAML attributes. This vulnerability [truncated]

HIGH logto-io CVE published 2026-07-10

CVE-2026-55377

CVE-2026-55377 is a high-severity vulnerability in Logto's Account Center step-up check. Prior to version 1.41.0, an attacker could create and verify a WebAuthn registration verification record using only an existing Account API bearer token. This allowed for MFA factor management without proving possession of an existing password, identifier, or MFA factor. The vulnerability has a CVSS score of 8.1 and i [truncated]

MEDIUM logto-io CVE published 2026-07-10

CVE-2026-55370

CVE-2026-55370 is a medium-severity vulnerability in Logto's TOTP verification process. An attacker can replay a successfully used TOTP code within the RFC 6238 acceptance window. This issue is fixed in version 1.41.0. The vulnerability affects users of Logto's authentication infrastructure who use TOTP for multi-factor authentication. The issue arises from the verifier using otplib's stateless check with [truncated]

MEDIUM logto-io CVE published 2026-07-10

CVE-2026-54714

CVE-2026-54714 is a reflected cross-site scripting (XSS) vulnerability in the Logto open-source auth infrastructure for SaaS and AI apps. The vulnerability exists in the SAML application flow, specifically in the @logto/core package. An attacker could inject script into the Logto tenant origin after a user completes login by crafting a RelayState value in the GET or POST /api/saml/:id/authn request. The i [truncated]