Sensitive Information Exposure in Predibase LoRAX by Predibase
CVE-2026-108858
6.8MEDIUM
What is CVE-2026-108858?
Predibase LoRAX versions up to 0.12.1 contain a vulnerability that allows sensitive API tokens to be logged in router logs. When users make a POST request to the /generate endpoint, the api_token provided can inadvertently be recorded. This misconfiguration can expose private information to malicious actors who gain access to the router logs or OTLP trace backends, allowing them to retrieve other users' private tokens. Organizations using this version should take immediate action to mitigate the risk.
Affected Version(s)
LoRAX 0 <= 0.12.1
