CVE-2026-63203
7.6 HIGHpublic exploit availablePublished 2026-09-24 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scope to retrieve stored social or enterprise SSO provider access tokens through GET /api/my-account/identities/{target}/access-token or GET /api/my-account/sso-identities/{connectorId}/access-token. The handlers authenticate the user but do not require the identities scope that protects neighboring identity-detail operations, bypassing the intended Account API consent boundary. Exploitation requires federated token-set storage to be enabled and the affected user to have authenticated through a supported connector. A low-trust application can use the disclosed provider token against upstream APIs within that token's granted scopes. This issue is fixed in version 1.42.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Weaknesses
CWE-862
Public exploit & PoC references
- https://github.com/logto-io/logto/commit/b560d17a4da4c25da95e3c73af4485d18ab7c224
- https://github.com/logto-io/logto/pull/9116
- https://github.com/logto-io/logto/releases/tag/v1.42.0
- https://github.com/logto-io/logto/security/advisories/GHSA-6g9q-qrx7-3jxf
- https://github.com/logto-io/logto/security/advisories/GHSA-6g9q-qrx7-3jxf
All references
- https://github.com/logto-io/logto/commit/b560d17a4da4c25da95e3c73af4485d18ab7c224
- https://github.com/logto-io/logto/pull/9116
- https://github.com/logto-io/logto/releases/tag/v1.42.0
- https://github.com/logto-io/logto/security/advisories/GHSA-6g9q-qrx7-3jxf
- https://github.com/logto-io/logto/security/advisories/GHSA-6g9q-qrx7-3jxf
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-14484
- MEDIUMCVE-2025-14486
- MEDIUMCVE-2025-14487
- UNSCOREDCVE-2026-100240
- MEDIUMCVE-2026-100287
- MEDIUMCVE-2026-100289
- MEDIUMCVE-2026-100303PoC
- MEDIUMCVE-2026-100305PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.