CVE WATCH / VULNERABILITY DETAIL

CVE-2026-63203

HIGHCVSS 7.6NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scope to retrieve stored social or enterprise S

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-63203 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-63203

HIGHCVSS 7.6NVD feed

Published 24 September 2026 · tracked since 25 September 2026

Description

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scope to retrieve stored social or enterprise S

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]