Skip to content
LowVulnerability

CVE-2026-108754: GPT-Load cleartext logging exposes client proxy keys in query strings

Identifier
CVE-2026-108754
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.

Summary

GPT-Load through 1.4.11 logs client proxy keys in cleartext. The Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Anyone with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.