Path Traversal Vulnerability in Canto SaaS API PHP Library
CVE-2026-55374
4.8MEDIUM
What is CVE-2026-55374?
The Canto SaaS API PHP library features a vulnerability in its Request::buildRequestUrl() method, which improperly joins path segment values without encoding, leading to potential path traversal exploits. When malicious actors control untrusted path variable inputs, they can manipulate request endpoints, enabling unauthorized read and write operations using the concerned application's privileges. This security flaw has been addressed in version 3.0.0, emphasizing the importance for users to upgrade to mitigate risks associated with this issue.
Affected Version(s)
canto-saas-api < 3.0.0
