Path Traversal Vulnerability in Sub2API AI Gateway Platform
CVE-2026-73079
8.5HIGH
What is CVE-2026-73079?
A path traversal vulnerability was identified in Sub2API, an AI API gateway platform used to manage API quotas from AI product subscriptions. This issue, present in versions 0.1.135 to 0.1.168, allows authenticated tenants to relay requests to arbitrary upstream endpoints. The flaw stems from the use of client-supplied subpaths without proper validation, leading to the possibility of misuse of pooled account credentials, potentially compromising sensitive APIs and endpoints. This vulnerability has been addressed in version 0.1.169.
Affected Version(s)
sub2api >= 0.1.135, <0.1.169
