CVE-2026-108754
Received Received - Intake

GPT-Load Proxy Key Exposure via Cleartext Logging

Vulnerability report for CVE-2026-108754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tbphp gpt-load 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GPT-Load through version 1.4.11 has a cleartext logging vulnerability where the Gin Logger middleware records the raw query string of requests before authentication middleware removes the proxy key parameter. This exposes client proxy keys in console logs or ./data/logs/app.log files.

Detection Guidance

Check logs for raw query strings containing proxy keys. Search ./data/logs/app.log and console output for URLs with key parameters. Use commands like grep -r 'key=' ./data/logs/ or tail -f ./data/logs/app.log to monitor logs in real-time.

Impact Analysis

Attackers with access to logs can extract proxy keys and misuse them against the associated group until the key is rotated. This requires local log access but does not lead to remote code execution or host compromise.

Compliance Impact

This vulnerability likely violates compliance requirements for protecting sensitive authentication credentials (proxy keys) under GDPR and HIPAA, as it involves unauthorized exposure of credentials in log files.

Mitigation Strategies

Upgrade to GPT-Load v2.0 or later which removes the vulnerable code path. If upgrading is not possible, disable the Gin Logger middleware or filter out key parameters from logs. Rotate all exposed proxy keys immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart