CVE-2026-55375Medium· 5.3▾ Sunlitcanto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing access logs, proxy logs, and APM traces to persist the credentials in plaintext. When a token request fails, OAuth2::obtainAccessToken() also passes the credential-bearing Guzzle request URI into AuthorizationFailedException, so application logs and error trackers can record the same secrets. An attacker with access to affected telemetry can obtain Canto credentials and use them to request access tokens for the tenant. This issue is fixed in version 3.0.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
jleehr/canto-saas-api <= 2.0.0Patched in:
jleehr/canto-saas-api 3.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55374Medium· 4.8canto-saas-api is a PHP library for interacting with the Canto SaaS API
CVE-2025-8852Medium· 4.3A vulnerability was identified in WuKongOpenSource WukongCRM 11.0
CVE-2024-23689High· 8.8Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…
CVE-2026-50157Medium· 6.5Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs
CVE-2023-0833Medium· 4.7A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value
CVE-2026-85709Medium· 5.3LightRAG: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses