Security Flaw in TensorZero Open-Source LLMOps Platform
CVE-2026-54457
7.7HIGH
What is CVE-2026-54457?
The TensorZero Gateway version prior to 2026.6.0 contains a vulnerability that allows a caller-supplied JSON 'storage_path' parameter to override the [object_storage] configuration dynamically. This flaw makes it possible for attackers to read arbitrary files from the gateway's filesystem, potentially exposing sensitive information such as credentials. Furthermore, if the S3-compatible storage type is selected, attackers can direct object-storage requests to internal or cloud-based metadata endpoints of their choosing. Exploiting this vulnerability can occur with either authenticated or unauthenticated access to the gateway, depending on the setup. This issue is resolved in version 2026.6.0.
Affected Version(s)
tensorzero < 2026.6.0
