logto-io logto

4 known vulnerabilities in logto-io logto, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-63203 CVSS 7.6 high Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in…
  • CVE-2026-56739 CVSS 8.5 high Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled…
  • CVE-2026-82263 CVSS 8.2 high Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to…
  • CVE-2026-82262 CVSS 8.2 high Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary…