VYPR

lorax

by Predibase

CVEs (1)

  • CVE-2026-108858MedOct 11, 2026
    risk 0.36cvss 5.5epss —

    Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users'…