{"data":{"id":"01407a48-8740-4973-8a3c-69ca272fedb1","title":"CVE-2026-108754: GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin…","summary":"GPT-Load through 1.4.11 logs client proxy keys in cleartext. The Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Anyone with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108754","publishedAt":"2026-10-11T13:17:20.380Z","cveId":"CVE-2026-108754","cweIds":["CWE-532"],"cvssScore":"3.3","cvssSeverity":"low","severity":"low","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["GPT-Load"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"GPT-Load cleartext logging exposes client proxy keys in query strings","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"local","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"epssCheckedAt":"2026-10-11T18:07:30.328Z","kevDateAdded":null,"advisoryAliases":["GHSA-cg67-pj93-c6m6"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-11T18:07:34.937Z","patchAvailable":null,"disclosureDate":"2026-10-11T13:17:20.380Z","capecIds":["CAPEC-215"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}