What is CVE-2026-63187?
CVE-2026-63187: A command injection vulnerability exists in Logto authentication infrastructure versions 1.40.1 to 1.41.0, where the commitlint workflow directly interpolates unsanitized PR titles into shell commands. This allows arbitrary code execution in the CI/CD pipeline via malicious pull request titles. Users should upgrade to version 1.41.0.
Azərbaycanca: CVE-2026-63187: Logto autentifikasiya platformasının 1.40.1-dən 1.41.0-a qədər versiyalarında, GitHub Actions iş axınında `github.event.pull_request.title` başlığının birbaşa əmrə daxil edilməsi səbəbindən əmr inyeksiyası (command injection) zəifliyi mövcuddur. Bu, zərərli PR başlığı vasitəsilə CI/CD mühitində özbaşına kod icrasına imkan verir. İstifadəçilər Logto-nu 1.41.0 versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
What can happen if CVE-2026-63187 in Logto is exploited?
This vulnerability allows arbitrary code execution in the CI/CD pipeline via a malicious pull request title in the GitHub Actions workflow.
Which versions of Logto are affected by CVE-2026-63187?
The vulnerability affects Logto versions 1.40.1 to 1.41.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.