{"api_version":"v1","generated_at":"2026-10-09T09:00:00+00:00","product":{"cve_count":11,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-logto-io-logto-4b8cee634021","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/logto","name":"logto","next_cursor":null,"observations":[{"affected":"logto: < 1.43.0","affected_versions_present":true,"cve_id":"CVE-2026-56739","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56739","fixed":"1.43.0.","last_modified":"2026-09-28T20:11:21.968Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-3556-624q-c5w3","primary_source":"","published":"2026-09-24T15:20:37.898Z"},{"affected":"logto: >= 1.31.0, < 1.42.0","affected_versions_present":true,"cve_id":"CVE-2026-63203","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63203","fixed":"1.42.0.","last_modified":"2026-09-24T15:47:41.056Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-6g9q-qrx7-3jxf","primary_source":"","published":"2026-09-24T15:18:32.273Z"},{"affected":"logto: \u2264 1.42.0","affected_versions_present":true,"cve_id":"CVE-2026-82263","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82263","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:19:54.723Z","patch_url":"","primary_source":"","published":"2026-08-28T16:18:48.639Z"},{"affected":"logto: \u2264 1.42.0","affected_versions_present":true,"cve_id":"CVE-2026-82262","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82262","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:19:53.810Z","patch_url":"","primary_source":"","published":"2026-08-28T16:18:47.953Z"},{"affected":">= 1.40.1, < 1.41.0","affected_versions_present":true,"cve_id":"CVE-2026-63187","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63187","fixed":"1.41.0.","last_modified":"2026-08-25T14:00:02.109Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-869c-8mm3-w5cj","primary_source":"","published":"2026-08-19T19:49:34.750Z"},{"affected":"< 0.3.9","affected_versions_present":true,"cve_id":"CVE-2026-63188","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63188","fixed":"0.3.9.","last_modified":"2026-08-21T21:48:40.521Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-rxjr-6c9q-h67x","primary_source":"","published":"2026-08-19T19:47:05.155Z"},{"affected":"< 1.41.0","affected_versions_present":true,"cve_id":"CVE-2026-62317","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62317","fixed":"1.41.0.","last_modified":"2026-08-21T19:05:49.589Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-qp7j-c3q2-g739","primary_source":"","published":"2026-08-19T19:41:23.800Z"},{"affected":"< 1.41.0","affected_versions_present":true,"cve_id":"CVE-2026-55377","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55377","fixed":"1.41.0.","last_modified":"2026-07-13T16:20:47.725Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-q4h3-38gc-4p4j","primary_source":"","published":"2026-07-10T19:57:58.088Z"},{"affected":"< 1.41.0","affected_versions_present":true,"cve_id":"CVE-2026-55370","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55370","fixed":"1.41.0.","last_modified":"2026-07-10T20:14:41.325Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-6wj7-c66m-6c82","primary_source":"","published":"2026-07-10T19:56:53.317Z"},{"affected":"< 1.41.0","affected_versions_present":true,"cve_id":"CVE-2026-55789","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55789","fixed":"1.41.0.","last_modified":"2026-07-13T18:16:18.449Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-vfpw-vq44-4p63","primary_source":"","published":"2026-07-10T19:55:37.360Z"},{"affected":"< 1.41.0","affected_versions_present":true,"cve_id":"CVE-2026-54714","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54714","fixed":"1.41.0.","last_modified":"2026-07-13T18:18:36.103Z","patch_url":"https://github.com/logto-io/logto/security/advisories/GHSA-cpm5-w86q-w85f","primary_source":"","published":"2026-07-10T19:54:28.526Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"logto-io"}}
