A vulnerability was found in Logto up to 1.37.1 and classified as critical. Impacted is an unknown function of the file packages/core/src/sso/OidcConnector/utils.ts. Executing a manipulation can lead to insufficient verification of data authenticity.

This vulnerability is registered as CVE-2026-15612. It is possible to launch the attack remotely. No exploit is available.