PatchSiren

Predibase CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Predibase CVE published 2026-10-11

CVE-2026-108858

CVE-2026-108858 debrief based on CVE Program and NVD records. Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability. The vulnerability writes caller-supplied api_token from POST /generate request bodies into router logs. This allows attackers with access to router logs or OTLP trace backends to recover other users' private-adapter tokens. LoRAX users and administrators sho [truncated]