Executive brief
Logto is an authentication and authorization platform used to manage user access and SSO for SaaS applications. An SSRF vulnerability in the OIDC connector creation endpoint allows tenant administrators with API credentials to trigger unauthorized requests to internal network services, potentially exposing sensitive data or accessing restricted systems.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Authenticated tenant administrators with Management API credentials can supply arbitrary internal URLs, causing the application to issue HTTP GET requests to private network services. The response content from these internal requests is returned in API responses, allowing attackers to probe or extract data from services they should not have direct access to. The issue affects Logto through version 1.42.0.
Affected products
- Logto Logto through 1.42.0
Timeline
- 2026-08-28: disclosed