VYPR

Gpt Load

by Tbphp

CVEs (1)

  • CVE-2026-108754LowOct 11, 2026
    risk 0.21cvss 3.3epss —

    GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can…