Known Vulnerabilities for Logto by Logto-io
Listed below are 10 of the newest known vulnerabilities associated with "Logto" by "Logto-io".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82263 json | Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fa... | Not Provided | 2026-08-28 | 2026-08-28 |
| CVE-2026-82262 json | Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accep... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-63188 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabl... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-63187 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflow... | Not Provided | 2026-08-19 | 2026-08-25 |
| CVE-2026-62317 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing block... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-55789 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML applicat... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55377 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-up ch... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-55370 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verificatio... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54714 json | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, @logto/core reflected the SAML Re... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-15617 json | Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthoriz... | Not Provided | 2026-07-23 | 2026-07-27 |