Security Flaw in TensorZero Open-Source LLMOps Platform
CVE-2026-54457

7.7HIGH

Key Information:

Vendor

Tensorzero

Vendor
CVE Published:
21 August 2026

What is CVE-2026-54457?

The TensorZero Gateway version prior to 2026.6.0 contains a vulnerability that allows a caller-supplied JSON 'storage_path' parameter to override the [object_storage] configuration dynamically. This flaw makes it possible for attackers to read arbitrary files from the gateway's filesystem, potentially exposing sensitive information such as credentials. Furthermore, if the S3-compatible storage type is selected, attackers can direct object-storage requests to internal or cloud-based metadata endpoints of their choosing. Exploiting this vulnerability can occur with either authenticated or unauthenticated access to the gateway, depending on the setup. This issue is resolved in version 2026.6.0.

Affected Version(s)

tensorzero < 2026.6.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.