Executive brief
Logto is an open-source authentication platform used to manage user identities for applications. A security flaw in its SAML identity provider component allowed users to inject malicious code into their own profile information, such as their name or email. Because this information was not properly cleaned before being included in security tokens, a regular user could trick the system into granting them administrative privileges or other unauthorized roles in connected applications.
Technical details
An XML injection vulnerability exists in Logto's self-hosted SAML application IdP due to the use of an outdated version of the 'samlify' library (2.10.0). The application performed string substitution of user-controlled profile attributes (like name and email) into element-text placeholders within a SAML XML template without proper escaping. An authenticated attacker could provide a crafted profile attribute containing XML markup to close existing tags and inject new ones, such as arbitrary roles or group memberships. Because these injected elements are included within the signed portion of the SAML assertion, relying Service Providers (SPs) would accept the forged attributes as authentic, leading to cross-application privilege escalation. The issue is resolved in version 1.41.0 by upgrading samlify to version 2.13.0 or higher.
Affected products
- logto-io Logto < 1.41.0
Timeline
- 2026-05-29: other: Vulnerability verified on live master branch
- 2026-06-30: patched: Fix merged and version 1.41.0 released
- 2026-07-01: advisory: GitHub Security Advisory published
- 2026-07-10: disclosed: CVE published to NVD