PT-2026-70269 · Sub2Api · Sub2Api

CVE-2026-73079

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sub2API versions 0.1.135 through 0.1.168
Description Sub2API is an AI API gateway platform that manages API quotas from AI product subscriptions. An issue exists where platform API keys issued to tenants are exchanged for upstream requests using shared provider accounts belonging to the operator. The POST /responses/*subpath endpoint fails to validate the client-supplied subpath when splicing it into the upstream URL. This allows an authenticated tenant to perform a path traversal, relaying requests to arbitrary upstream endpoints using the operator's pooled account credentials.
Recommendations Update Sub2API to version 0.1.169.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73079
GHSA-VRXQ-QM4H-6HGG

Affected Products

Sub2Api