CVE-2026-108754
MEDIUM
4,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,3
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.
532
Insertion of Sensitive Information into Log File
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
All platforms may be affected
https://github.com/tbphp/gpt-load
https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d…
https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d…
https://hackmd.io/@haind03/tbphp-gpt-load-proxy-key-access-log-disclosure
https://www.vulncheck.com/advisories/gpt-load-through-1.4.11-cleartext-proxy-ke…