jleehr/canto-saas-api
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting jleehr/canto-saas-apipage 1 of 1
- CVE-2026-55374MEDIUMCVSS 4.8EG 4.8✓ Fixed in 3.0.02026-06-19
vulnerable: 1.0.3, 2.0.0
canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the schem…
- CVE-2026-55375MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.0.02026-06-19
vulnerable: 1.0.3, 2.0.0
canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing ac…
Check whether jleehr/canto-saas-api is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for jleehr/canto-saas-api CVEs against the assets you own.
Start Free Scan →