GHSA-257m-4vpx-xg86CriticalCVSS 9.1
Logto performs principal lookup without normalizing email and identifier strings, enabling...
🔗 CVE IDs covered (1)
📋 Description
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.