MEDIUM
Predibase
CVE published 2026-10-11
CVE-2026-108858
CVE-2026-108858 debrief based on CVE Program and NVD records. Predibase LoRAX through 0.12.1 contains a sensitive information exposure vulnerability. The vulnerability writes caller-supplied api_token from POST /generate request bodies into router logs. This allows attackers with access to router logs or OTLP trace backends to recover other users' private-adapter tokens. LoRAX users and administrators sho [truncated]