← Volver al buscador de CVEs

CVE-2026-63187

Logto

Descripción

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto-s .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step-s inline echo command before piping the title to npx commitlint. A pull request title containing a single quote could terminate the echo string and append arbitrary shell commands on the GitHub Actions runner. The pull_request trigger used a read-only GITHUB_TOKEN and did not expose repository secrets, but injected commands could alter or disrupt the ephemeral workflow execution. This issue is fixed in version 1.41.0.

CVSS 6.3EPSS 0.299%Riesgo 0.65
Ver fuente
Publicación
2026-08-19 20:17:20
Versiones afectadas
>=1.40.1,<1.41.0
Tipo
Aplicación web
Última modificación
2026-08-25 14:16:53
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L