Sceawere

Vulnerability Detail

CVE-2026-108754UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GPT-Load Cleartext Proxy Key Exposure

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
4h ago
Vendor
tbphp
Product
gpt-load
Attack Type
Insertion of Sensitive Information into Log File
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-11T13:17:20.380Z",
  "pubdate": "2026-10-11T13:17:20.380Z",
  "executiveSummary": "GPT-Load versions through 1.4.11 are susceptible to a cleartext logging vulnerability involving the exposure of sensitive client proxy keys.\nThe flaw originates from an improper execution order within the Gin Logger middleware, which captures the raw HTTP request, including query parameters, before the application's sanitization logic (extractAuthKey) can redact sensitive information.\nThis vulnerability results in the persistent storage of authentication credentials in local application logs, specifically './data/logs/app.log'.\nAn attacker possessing local or remote read access to these log files can exfiltrate proxy keys associated with Gemini-style API requests.\nOnce obtained, these keys allow unauthorized actors to impersonate legitimate clients and utilize the target's proxy infrastructure, leading to potential service abuse, unauthorized cost accrual, or data interception.\nThe risk is significant due to the sensitivity of proxy keys and the ubiquity of log files in production environments, which are often accessible to automated monitoring tools, backup systems, or internal users with low-level privileges.",
  "technicalDetails": "The vulnerability resides in the interaction between the Gin Logger middleware and the request processing pipeline of the GPT-Load application. In versions 1.4.11 and below, the Gin Logger is configured to intercept incoming HTTP requests at the beginning of the middleware chain.\nThe root cause of the exposure is a sequencing error in the request lifecycle: the logging middleware processes the raw request object—containing the full, unredacted URI—before the application's internal extractAuthKey function is invoked to strip or mask the 'key' parameter from the request metadata.\nBecause the logger captures the state of the request object at this premature stage, the full query string is committed to the persistence layer.\nThis results in sensitive authentication tokens being written to the file system in cleartext, specifically within './data/logs/app.log'.\nThe exploitation process follows a predictable pattern: 1) An attacker monitors the application logs, either through legitimate access to the server filesystem or by exploiting a secondary vulnerability such as Local File Inclusion (LFI) or an exposed log aggregation endpoint. 2) The attacker identifies Gemini-style request signatures within the logs that contain the 'key' parameter in the query string. 3) The attacker parses these logs to extract the cleartext proxy keys. 4) With the stolen keys, the attacker issues unauthorized requests through the proxy group associated with the compromised credential.\nThis behavior bypasses standard security controls because the exposure occurs 'at rest' within the logs, rather than 'in transit' over the network. The impact is severe as it effectively delegates authentication authority to any entity capable of reading log files. This does not require advanced network interception capabilities, merely sufficient privilege to read application output. There is no requirement for the attacker to maintain a persistent connection; the logs act as a historical repository of credentials, allowing for retrospective exploitation of historical data long after the initial request has been processed."
}
CVE-2026-108754: GPT-Load Cleartext Proxy Key Exposure (LOW Severity, CVSS: 3.3) | Sceawere