Impact
GPUStack v2.2.1 and earlier contain an unauthenticated endpoint flaw that lets attackers access rich inference logs, adjust log levels, and read memory profiling data without authentication, exposing prompts, completions, and configuration details. The flaw is a classic CWE‑306: Unauthenticated Access to Sensitive Information.
Affected Systems
Vulnerable versions are gpustack:gpustack up to and including 2.2.1. Firmware before commit 4e20551 was fixed; upgrading to any release that incorporates the 4e20551 commit removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 highlights a severe impact, but the EPSS score of <1% indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is connecting to the worker port exposed on a network; based on the description, it is inferred that remote attackers with network reach can immediately read logs or modify worker configuration because no authentication is required.
OpenCVE Enrichment