CVE-2026-33183
Last modified
CVE-2026-33183 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file paths under the configured fixture directory without validation. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file paths under the configured fixture directory without validation. A name containing path segments (e.g. ../traversal or ../../etc/passwd) resulted in a path outside that directory. When the application read a fixture (e.g. for mocking) or wrote one (e.g. when recording responses), it could read or write files anywhere the process had access. If the fixture name was derived from user or attacker-controlled input (e.g. request parameters or config), this constituted a path traversal vulnerability and could lead to disclosure of sensitive files or overwriting of critical files. The fix in version 4.0.0 adds validation in the fixture layer (rejecting names with /, \, .., or null bytes, and restricting to a safe character set) and defense-in-depth in the storage layer (ensuring the resolved path remains under the base directory before any read or write).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Saloon | Saloon | < 4.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33183?
How severe is CVE-2026-33183?
How do I fix CVE-2026-33183?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33177Statamic is a Laravel and Git powered content management sys…4.3
- CVE-2026-33179libfuse is the reference implementation of the Linux FUSE. F…5.5
- CVE-2026-3318Open redirection vulnerability in the latest demo version of…5.3
- CVE-2026-33180HAPI FHIR is a complete implementation of the HL7 FHIR stand…7.5
- CVE-2026-33181Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-33182Saloon is a PHP library that gives users tools to build API …7.5
- CVE-2026-33184nimiq/core-rs-albatross is a Rust implementation of the Nimi…7.5
- CVE-2026-33185Discourse is an open-source discussion platform. From versio…5
- CVE-2026-33186gRPC-Go is the Go language implementation of gRPC. Versions …9.1
- CVE-2026-33187Rejected reason: Further research determined the issue origi…
- CVE-2026-33188Rejected reason: Further research determined the issue origi…
- CVE-2026-33189Rejected reason: Further research determined the issue origi…
Are you affected by CVE-2026-33183?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
