Description
GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.
Published: 2026-10-11
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Credential Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability stems from the Gin Logger middleware capturing the raw query string before the authentication key is stripped. Because the logger writes the unmodified query to console logs and the local app.log file, any process that can read these logs can retrieve the proxy key embedded in Gemini-style requests. Once an attacker has the key, they can impersonate the client and access the group associated with that key.

Affected Systems

The affected product is tbphp's GPT-Load, up through version 1.4.11. Any installation of GPT-Load prior to the fix must be considered vulnerable. The issue resides in the internal middleware component responsible for request handling. Users should verify the installed version against the version mentioned in the advisory.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate risk; no EPSS data is available and the vulnerability is not listed in CISA KEV. Exploitation requires read access to the application logs, typically available to local users or those who can compromise the system. Therefore, timely patching and hardening of log access are essential.

Generated by OpenCVE AI on October 11, 2026 at 14:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update GPT-Load to a version released after 1.4.11 where the logging issue has been fixed.
  • Restrict file permissions on console and app.log files so that only authorized processes can read them.
  • Configure the Gin Logger to exclude or mask query string parameters that contain sensitive proxy keys.

Generated by OpenCVE AI on October 11, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description GPT-Load through 1.4.11 contains a cleartext logging vulnerability that exposes client proxy keys because the Gin Logger middleware records the raw query string before extractAuthKey strips the key parameter. Attackers with read access to console logs or ./data/logs/app.log can recover proxy keys from Gemini-style requests and use them against the corresponding group.
Title GPT-Load through 1.4.11 Cleartext Proxy Key Logging via Access Logger
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:53.343Z

Reserved: 2026-10-11T01:54:18.301Z

Link: CVE-2026-108754

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:20.380

Modified: 2026-10-11T13:17:20.380

Link: CVE-2026-108754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File