CVE-2026-108858
Predibase LoRAX through 0.12.1 API Token Exposure via Router Logs
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability that writes the caller-supplied api_token from POST /generate request bodies into router logs. Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field.
| CWE | CWE-532 |
| Vendor | predibase |
| Product | lorax |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for predibase lorax
Be the first to know when new medium vulnerabilities affecting predibase lorax are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Predibase / LoRAX
0 โค 0.12.1
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/predibase-lorax-generate-api-token-logging github.com: https://github.com/predibase/lorax/blob/c0e5798318a6b826572c612ddd4cf44621aa4add/router/src/server.rs#L584-L596 github.com: https://github.com/predibase/lorax/blob/c0e5798318a6b826572c612ddd4cf44621aa4add/router/src/lib.rs#L182-L188 github.com: https://github.com/predibase/lorax vulncheck.com: https://www.vulncheck.com/advisories/predibase-lorax-through-0.12.1-api-token-exposure-via-router-logs
Credits
hieuPenguinnn