Path Traversal Vulnerability in Canto SaaS API PHP Library
CVE-2026-55374

4.8MEDIUM

Key Information:

Vendor

Jleehr

Vendor
CVE Published:
15 September 2026

What is CVE-2026-55374?

The Canto SaaS API PHP library features a vulnerability in its Request::buildRequestUrl() method, which improperly joins path segment values without encoding, leading to potential path traversal exploits. When malicious actors control untrusted path variable inputs, they can manipulate request endpoints, enabling unauthorized read and write operations using the concerned application's privileges. This security flaw has been addressed in version 3.0.0, emphasizing the importance for users to upgrade to mitigate risks associated with this issue.

Affected Version(s)

canto-saas-api < 3.0.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.