Path Traversal Vulnerability in Sub2API AI Gateway Platform
CVE-2026-73079

8.5HIGH

Key Information:

Vendor

Wei-shaw

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73079?

A path traversal vulnerability was identified in Sub2API, an AI API gateway platform used to manage API quotas from AI product subscriptions. This issue, present in versions 0.1.135 to 0.1.168, allows authenticated tenants to relay requests to arbitrary upstream endpoints. The flaw stems from the use of client-supplied subpaths without proper validation, leading to the possibility of misuse of pooled account credentials, potentially compromising sensitive APIs and endpoints. This vulnerability has been addressed in version 0.1.169.

Affected Version(s)

sub2api >= 0.1.135, <0.1.169

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.