PT-2026-57279 · Logto · Logto

CVE-2026-54714

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Logto versions prior to 1.41.0
Description In the @logto/core package, the software fails to perform HTML-attribute escaping when reflecting the RelayState, SAMLResponse, and actionUrl variables into an auto-submit HTML form within the packages/core/src/saml-application/SamlApplication/utils.ts file. An attacker can use a crafted RelayState via the /api/saml/:id/authn endpoint (supporting GET or POST methods) to inject scripts that execute on the Logto tenant origin after a user completes the login process.
Recommendations Update to version 1.41.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54714
GHSA-CPM5-W86Q-W85F

Affected Products

Logto