CVE-2026-108754 PUBLISHED

GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor tbphp
Product gpt-load
Versions Default: unaffected
  • affected from 0 to 1.4.11 (incl.)

Credits

  • HaiND from the Post and Telecommunication Institute of Technology finder

References

Problem Types

  • Insertion of Sensitive Information into Log File CWE