VYPR
Low severity3.3NVD Advisory· Published Oct 11, 2026

CVE-2026-108754

CVE-2026-108754

Description

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

Affected products

2
  • Tbphp/Gpt Loadreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=1.4.11

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.