Back to news
regulationSub2API2026-08-08

Sub2API discloses CVSS 8.8 OAuth account-takeover vulnerability

On August 8, Sub2API disclosed a CVSS 8.8 OAuth account-takeover vulnerability affecting v0.1.171 and earlier, exploitable with only the victim's registered email.

On August 8, Sub2API publicly disclosed a CVSS 8.8 high-severity OAuth security vulnerability affecting v0.1.171 and earlier. Attackers only need the victim's registered email, no password, no SMS code, and no victim interaction, to bind their own OAuth identity to the target account and take over the account entirely, including the victim's API keys, billing balance, and service subscription quotas.

The root cause is the existingUser branch in the pending session flow, which is missing password and verification-code validation. Attackers simply fill in the victim's user ID to complete OAuth identity binding. Subsequent login with the attacker's OAuth credential maps directly to the victim's business account.

According to the disclosure, attackers had already exploited the vulnerability in the early morning to log into victim sites, create large numbers of API keys, and consume balances. Site customer support staff noticed the anomaly and found attackers even chatting with them through the keys. Sub2API has fixed the vulnerability in v0.1.172 and urges all users to upgrade immediately.

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. The incident has reignited developer community attention to the security of relay platforms.

Sub2APIOAuthCVE账户接管CVSS 8.8