PT-2026-57279 · Logto · Logto
CVE-2026-54714
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Logto versions prior to 1.41.0
Description
In the
@logto/core package, the software fails to perform HTML-attribute escaping when reflecting the RelayState, SAMLResponse, and actionUrl variables into an auto-submit HTML form within the packages/core/src/saml-application/SamlApplication/utils.ts file. An attacker can use a crafted RelayState via the /api/saml/:id/authn endpoint (supporting GET or POST methods) to inject scripts that execute on the Logto tenant origin after a user completes the login process.Recommendations
Update to version 1.41.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Logto