Sceawere
Vulnerability Detail
CVE-2026-108858UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Predibase LoRAX Sensitive Token Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- Predibase
- Product
- LoRAX
- Attack Type
- Insertion of Sensitive Information into Log File
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-11T14:17:05.640Z",
"pubdate": "2026-10-11T14:17:05.640Z",
"executiveSummary": "Predibase LoRAX versions through 0.12.1 are susceptible to a sensitive information exposure vulnerability occurring within the logging and telemetry subsystem.\nThe vulnerability manifests when the application incorrectly processes the 'api_token' field provided in the body of POST /generate requests.\nSpecifically, the router implementation captures this sensitive credential and persists it within router logs and OTLP (OpenTelemetry Protocol) trace backends.\nThis behavior exposes private-adapter tokens belonging to arbitrary users to any entity with read access to the centralized logging infrastructure or observability platform.\nThe risk is critical for multi-tenant environments where internal logs are ingested into third-party or shared monitoring systems, as it facilitates the unauthorized extraction of credentials used for authenticated adapter access.\nNo specific authentication or privilege escalation is required to trigger the logging event, as the vulnerability is inherent to the request processing logic of the /generate endpoint.\nSuccessful exploitation allows an attacker to harvest credentials, potentially leading to unauthorized model adapter usage or lateral movement within the infrastructure if those tokens provide broader access.",
"technicalDetails": "The root cause of this vulnerability lies in the improper instrumentation of the request handling pipeline within the LoRAX router component. During the execution of the POST /generate endpoint, the application receives a JSON payload containing several parameters, including 'api_token'.\nThe router implementation utilizes OpenTelemetry (OTLP) instrumentation to create spans for the 'GenerateParameters' operation. In affected versions (0.12.1 and below), the application logic mistakenly includes the entire contents of the request parameters object—which contains the 'api_token' field—as an attribute or metadata associated with the instrumented span.\nBecause standard logging configurations and OTLP collectors often capture and persist span metadata to diagnostic storage, these tokens are inadvertently written to disk-based logs and distributed tracing backends.\nThe attack flow proceeds as follows: 1) A legitimate user submits a request to the /generate endpoint, embedding a private-adapter token in the request body for authentication or authorization against a specific adapter. 2) The LoRAX router intercepts the request and serializes the parameters for trace instrumentation. 3) The OTLP middleware propagates these parameters into the tracing infrastructure, effectively leaking the token in plaintext. 4) An attacker with read access to the logging aggregator (e.g., ELK stack, Grafana Loki, or Jaeger) queries for the specific span tags or log patterns associated with the 'GenerateParameters' operation. 5) The attacker extracts the 'api_token' from the retrieved diagnostic data.\nThis vulnerability constitutes a design flaw in how the application manages the lifecycle of sensitive request parameters versus diagnostic data. The exposure is persistent, meaning logs generated prior to patching remain a source of credential leakage. The scope of impact is highly dependent on the log retention policy of the host environment, as these logs often aggregate sensitive data long after the individual requests have been fulfilled. Furthermore, because OTLP spans are frequently forwarded to external observability SaaS providers, the exposure may extend beyond the immediate infrastructure boundaries, increasing the risk of data exfiltration and credential misuse by third-party logging providers."
}