CVE-2026-108754

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,8
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW 3,3
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

532

Insertion of Sensitive Information into Log File

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/tbphp/gpt-load
https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d…
https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d…
https://hackmd.io/@haind03/tbphp-gpt-load-proxy-key-access-log-disclosure
https://www.vulncheck.com/advisories/gpt-load-through-1.4.11-cleartext-proxy-ke…