Skip to content

Coordinated security disclosure request: timing-based user enumeration on password verify #8773

Description

@eddieran

Hi @Silverhand-tw and the Logto team,

A second coordinated security disclosure (separate from #8772). I identified an information-disclosure issue in the experience password-verification flow (packages/core/src/libraries/user.ts verifyUserPassword). To avoid disclosing the bug class on a public issue, this thread is intentionally light on detail.

Same routing question as #8772 — please either enable PVR or share a security contact email and I will send the report privately. CC contact@logto.io.

This is the same bug class previously disclosed against zitadel as GHSA-jq8w-8q2f-ffm9 and GHSA-83cg-9mwq-gj42, included for context.

Reporter: edding.suree@gmail.com
Reference: LOGTO-002 (TS top-50 audit campaign)

Thanks!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions