Vulnerabilidades en logto-io
9 resultadosAnálisis Vexday
Logto-io apresenta 4 vulnerabilidades registradas na base, todas publicadas nos últimos 90 dias, indicando um fornecedor com histórico recente de exposições. Nenhuma das vulnerabilidades está sob exploração ativa (KEV) ou classificada como crítica, reduzindo significativamente o risco imediato. A fraqueza dominante (CWE-1395) sugere problemas estruturais na implementação que merecem atenção prioritária em avaliações de adoção.
CVE-2026-62317HIGHLogto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing)EPSS 0.6%CVE-2026-55377HIGHLogto: Account Center MFA management step-up bypass via WebAuthn registration verificationEPSS 0.5%CVE-2026-63188HIGHlogto-tunnel serves files outside --experience-path via path traversalEPSS 0.4%CVE-2026-55789HIGHLogto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service ProvidersEPSS 0.4%CVE-2026-63187MEDIUMLogto: OS command injection vulnerability exists in the Commitlint workflowEPSS 0.4%CVE-2026-54714MEDIUMLogto: XSS via unescaped RelayState in SAML auto-submit formEPSS 0.3%CVE-2026-55370MEDIUMLogto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)EPSS 0.3%CVE-2026-82262HIGHLogto Server-Side Request Forgery via webhook test endpointEPSS 0.3%CVE-2026-82263HIGHLogto Server-Side Request Forgery via OIDC SSO Connector Issuer URLEPSS 0.3%