Impact
Logto does not enforce nonce validation when the nonce claim is missing from an id_token, allowing an attacker to replay an authentication token and gain unauthorized access to an established session. The flaw undermines the intended binding between the authentication request and the resulting session, effectively weakening session integrity and confidentiality.
Affected Systems
Logto:Logto is affected. No specific version information is provided in the entry.
Risk and Exploitability
The flaw is remotely exploitable through standard OIDC flows by an attacker who can capture an id_token lacking a nonce and repeat it to hijack a session. The EPSS score is below 1%, indicating a low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the weakness permits arbitrary session takeover, it poses a significant risk to any system relying on Logto for identity management. The lack of an immediate product downgrade or other mitigations means the risk is contingent on the technical ability of the attacker to intercept or create malicious id_tokens.
OpenCVE Enrichment