LowVulnerability
CVE-2026-108754: GPT-Load cleartext logging exposes client proxy keys in query strings
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108754
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
GPT-Load through 1.4.11 logs client proxy keys in cleartext. The Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Anyone with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- InfoPrivacy Risks and Leakage Pathways in Agentic and Multi-Agent AI SystemsSimilar attack · ACM Digital Library (TOPS, DTRAP, CSUR)
- MediumCVE-2026-108592: mini-swe-agent information exposure in BubblewrapEnvironment sandboxSimilar attack · NVD/CVE Database
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes fail open when masking credentials in proxy responsesSimilar attack · NVD/CVE Database
- InfoAnytime-valid detection of LLM weight exfiltrationSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)