Impact
Logto’s SAML Identity Provider built signed assertions by inserting user‑controlled profile attributes directly into an XML template without escaping. A low‑privilege authenticated user could place XML markup in a profile such as name or custom attributes, causing Logto to sign a forged SAML attribute—e.g., a role—to the assertion. When the relying Service Provider trusts and authorizes on such attributes, the attacker gains elevated privileges. The weakness is a form of XML Injection and improper input validation.
Affected Systems
The vulnerability affects logto‑io’s Logto product. All releases prior to 1.41.0 are vulnerable. The issue is resolved in Logto 1.41.0; upgrading to that release or later removes the flaw.
Risk and Exploitability
The CVSS score of 8.5 places the issue in the high‑severity range. EPSS is <1%, indicating a very low exploitation probability, but the flaw enables privilege escalation through crafted SAML assertions by an authenticated low‑privilege user. The likely exploitation vector is an authenticated session on the Logto IdP where the user can modify profile attributes; once the forged assertion is sent to the Service Provider, the attacker’s elevated role is accepted. Because denial of service or data exfiltration is not the primary concern, the risk centers on the damage caused by privilege escalation and the potential for cascading compromise at relying applications. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment