{"data":{"id":"c19cbd16-186e-4b3d-b615-2ae47f8f2990","title":"CVE-2026-73079: Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0","summary":"Sub2API is a platform that manages API access (the ability to use AI services) by distributing shared accounts across multiple users. In versions 0.1.135 to 0.1.168, an authenticated user could manipulate the URL path to send requests to unintended servers using the platform's shared account credentials, because the system didn't validate where requests were being sent. This vulnerability was caused by path traversal (exploiting how the system handles file/URL paths without checking them).","solution":"This vulnerability is fixed in version 0.1.169.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73079","publishedAt":"2026-08-11T16:17:39.713Z","cveId":"CVE-2026-73079","cweIds":["CWE-22","CWE-441"],"cvssScore":"8.5","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["Sub2API","ChatGPT","Codex","OpenAI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-11T16:17:39.713Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}