Sceawere
Vulnerability Detail
CVE-2026-108857UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Hugging Face TEI API Key Exposure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.3
- Creation Date
- 3h ago
- Vendor
- Hugging Face
- Product
- Text Embeddings Inference
- Attack Type
- Insertion of Sensitive Information into Log File
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Hugging Face Text Embeddings Inference through 1.9.4 contains a cleartext logging vulnerability that exposes the configured api_key because the router's Args struct lacks a redact attribute for it. Attackers with access to router logs, container output, or OTLP telemetry can recover the Bearer token and call the protected embedding and rerank endpoints.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.3",
"pubDate": "2026-10-11T14:17:05.503Z",
"pubdate": "2026-10-11T14:17:05.503Z",
"executiveSummary": "Hugging Face Text Embeddings Inference (TEI) versions through 1.9.4 are susceptible to a cleartext logging vulnerability involving sensitive API credentials.\nThe vulnerability stems from the absence of a redaction attribute within the router's configuration struct, causing the 'api_key' to be emitted in plaintext within application logs, container standard output, and OTLP telemetry streams.\nThis flaw enables unauthorized actors with read access to log aggregation systems or container runtime environments to exfiltrate Bearer tokens.\nSuccessful exploitation allows attackers to perform authenticated requests against protected embedding and rerank endpoints, effectively bypassing authentication controls.\nThe risk is critical for environments where telemetry and logging data are accessible to non-administrative users or third-party log management services.",
"technicalDetails": "The root cause of this vulnerability lies in the implementation of the Args struct within the Hugging Face Text Embeddings Inference router component.\nIn versions 1.9.4 and earlier, the configuration structure lacks the necessary metadata or masking directives required to instruct the logging subsystem to omit or redact sensitive fields when serializing the configuration for diagnostic or startup output.\nWhen the router initializes, it logs its configuration state; because the 'api_key' field is treated as a standard string parameter without protective tagging, the raw credential is written to the configured log destination.\nThe attack flow proceeds as follows: First, an attacker gains unauthorized read access to the application logs, container runtime logs (via 'docker logs' or 'kubectl logs'), or a centralized OTLP (OpenTelemetry Protocol) collector instance.\nSecond, the attacker parses these logs to identify entries containing the 'api_key' variable associated with the router configuration.\nThird, once the Bearer token is extracted, the attacker crafts malicious HTTP requests targeting the exposed embedding or rerank endpoints, inserting the intercepted credential into the 'Authorization: Bearer <api_key>' header.\nThe vulnerable component is the router module, specifically the initialization logic that handles the parsing and logging of arguments provided at runtime.\nThere are no specific network prerequisites for the initial vulnerability; however, the impact is magnified by the exposure of telemetry or logging infrastructure. Post-exploitation, the attacker assumes the identity of the authenticated client, allowing for unauthorized model inference, potential data exfiltration, or resource exhaustion by saturating the protected inference endpoints.\nBecause the logging mechanism operates independently of the request-handling authentication logic, the vulnerability effectively converts a hardened authentication mechanism into a plaintext disclosure vector, nullifying the security posture of the protected endpoints."
}