Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field. | |
| Title | Predibase LoRAX through 0.12.1 API Token Exposure via Router Logs | |
| Weaknesses | CWE-532 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T13:26:05.793Z
Reserved: 2026-10-11T13:06:48.900Z
Link: CVE-2026-108858
No data.
Status : Received
Published: 2026-10-11T14:17:05.640
Modified: 2026-10-11T14:17:05.640
Link: CVE-2026-108858
No data.
OpenCVE Enrichment
No data.
Weaknesses