Impact
The vulnerability stems from the Gin Logger middleware capturing the raw query string before the authentication key is stripped. Because the logger writes the unmodified query to console logs and the local app.log file, any process that can read these logs can retrieve the proxy key embedded in Gemini-style requests. Once an attacker has the key, they can impersonate the client and access the group associated with that key.
Affected Systems
The affected product is tbphp's GPT-Load, up through version 1.4.11. Any installation of GPT-Load prior to the fix must be considered vulnerable. The issue resides in the internal middleware component responsible for request handling. Users should verify the installed version against the version mentioned in the advisory.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate risk; no EPSS data is available and the vulnerability is not listed in CISA KEV. Exploitation requires read access to the application logs, typically available to local users or those who can compromise the system. Therefore, timely patching and hardening of log access are essential.
OpenCVE Enrichment