Cleartext Logging Vulnerability in GPT-Load Affects Client Proxy Keys
CVE-2026-108754
4.8MEDIUM
What is CVE-2026-108754?
GPT-Load versions up to 1.4.11 exhibit a cleartext logging vulnerability which compromises client proxy keys. The Gin Logger middleware records the unaltered query string before it is sanitized to strip out the key parameter. This flaw allows attackers with read access to logs — specifically the console logs or ./data/logs/app.log — to retrieve sensitive proxy keys used in Gemini-style requests, enabling them to misuse these keys against the relevant user groups.
Affected Version(s)
gpt-load 0 <= 1.4.11
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
