Cleartext Logging Vulnerability in GPT-Load Affects Client Proxy Keys
CVE-2026-108754

4.8MEDIUM

Key Information:

Vendor

TbPHP

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108754?

GPT-Load versions up to 1.4.11 exhibit a cleartext logging vulnerability which compromises client proxy keys. The Gin Logger middleware records the unaltered query string before it is sanitized to strip out the key parameter. This flaw allows attackers with read access to logs — specifically the console logs or ./data/logs/app.log — to retrieve sensitive proxy keys used in Gemini-style requests, enabling them to misuse these keys against the relevant user groups.

Affected Version(s)

gpt-load 0 <= 1.4.11

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.