{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108754", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-11T01:54:18.301Z", "datePublished": "2026-10-11T12:19:53.343Z", "dateUpdated": "2026-10-11T12:19:53.343Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-11T12:19:53.343Z" }, "datePublic": "2026-10-10T00:00:00.000Z", "title": "GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger", "descriptions": [ { "lang": "en", "value": "GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Insertion of Sensitive Information into Log File", "cweId": "CWE-532", "type": "CWE" } ] } ], "affected": [ { "vendor": "tbphp", "product": "gpt-load", "defaultStatus": "unaffected", "versions": [ { "version": "0", "lessThanOrEqual": "1.4.11", "status": "affected", "versionType": "semver" } ], "packageURL": "pkg:github/tbphp/gpt-load", "repo": "https://github.com/tbphp/gpt-load" } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N", "attackVector": "LOCAL", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 4.8, "baseSeverity": "MEDIUM" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 3.3, "baseSeverity": "LOW" } } ], "references": [ { "url": "https://hackmd.io/@haind03/tbphp-gpt-load-proxy-key-access-log-disclosure", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d/internal/middleware/middleware.go#L20-L74", "tags": [ "technical-description" ] }, { "url": "https://github.com/tbphp/gpt-load/blob/a12882be9e06011da5e0284db5dd4617a7ca6e6d/internal/middleware/middleware.go#L247-L254", "tags": [ "technical-description" ] }, { "url": "https://github.com/tbphp/gpt-load", "tags": [ "product" ] }, { "name": "VulnCheck Advisory: GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/gpt-load-through-1.4.11-cleartext-proxy-key-logging-via-access-logger" } ], "credits": [ { "lang": "en", "value": "HaiND from the Post and Telecommunication Institute of Technology", "type": "finder" } ], "x_generator": { "engine": "vulncheck-endgame" } } } }