CVE-2026-63203

CVE-2026-63203 published: Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with only the openid scop...

View full NVD advisory → ← Back to CVE watch