Sensitive Information Exposure in Predibase LoRAX by Predibase
CVE-2026-108858

6.8MEDIUM

Key Information:

Vendor

Predibase

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108858?

Predibase LoRAX versions up to 0.12.1 contain a vulnerability that allows sensitive API tokens to be logged in router logs. When users make a POST request to the /generate endpoint, the api_token provided can inadvertently be recorded. This misconfiguration can expose private information to malicious actors who gain access to the router logs or OTLP trace backends, allowing them to retrieve other users' private tokens. Organizations using this version should take immediate action to mitigate the risk.

Affected Version(s)

LoRAX 0 <= 0.12.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.