VYPR

TensorZero Gateway

by TensorZero

CVEs (1)

  • CVE-2026-54457higJul 15, 2026
    risk 0.45cvss epss

    ### Impact The `/internal/object_storage` endpoint accepts a caller-supplied JSON `storage_path` parameter that dynamically overrides the TensorZero `[object_storage]` configuration. By abusing the `filesystem` storage type, a caller can read arbitrary files from the gateway…