CVE-2026-108858
Received Received - Intake

Sensitive Information Exposure in Predibase LoRAX

Vulnerability report for CVE-2026-108858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Predibase LoRAX 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Predibase LoRAX through version 0.12.1 has a flaw where it logs sensitive API tokens from POST /generate request bodies into router logs. This happens when the api_token is recorded in the instrumented GenerateParameters span field. Attackers with access to these logs or OTLP trace backends can extract other users' private-adapter tokens.

Detection Guidance

Check router logs or OTLP trace backends for the instrumented GenerateParameters span field containing api_token values. Search logs for POST /generate request bodies that may have been logged.

Impact Analysis

If you use Predibase LoRAX 0.12.1 or earlier, attackers with log access could steal your API tokens. This may lead to unauthorized access to your systems, data breaches, or misuse of your resources. The impact depends on the permissions tied to the exposed tokens.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data if tokens grant access to such data. For HIPAA, it may risk protected health information exposure. Non-compliance fines or penalties could apply if controls to protect sensitive data are inadequate.

Mitigation Strategies

Upgrade Predibase LoRAX to a version that fixes the sensitive information exposure issue. Review and sanitize router logs to remove any stored api_token values. Disable logging of request bodies if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart