CVE Explorer
CVE-2026-33182
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector's base URL with the request endpoint. If the endpoint was a valid absolute URL, the code used that URL as-is and ignored the base URL. The request—and any authentication headers, cookies, or tokens attached by the connector—was then sent to the attacker-controlled host. If the endpoint could be influenced by user input or configur
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"saloon","vendor":"saloonphp","versions":[{"status":"affected","version":"< 4.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.6,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4","tags":["x_refsource_MISC"],"url":"https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/references/1
{"name":"https://github.com/saloonphp/saloon/security/advisories/GHSA-c83f-3xp6-hfcp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/saloonphp/saloon/security/advisories/GHSA-c83f-3xp6-hfcp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:985c9823ebbd9948b87ddb96e90fe51ed1aaf79dc060a69390666c8d37f798ed · sha256:d89d519ec1d5eeeb… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.