PatchSiren

tensorzero CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH tensorzero CVE published 2026-08-21

CVE-2026-54457

CVE-2026-54457 is a high-severity vulnerability in the TensorZero LLMOps platform that allows for arbitrary file reads and unauthorized outbound requests. The issue, fixed in version 2026.6.0, requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This vulnerability has significant implications for defenders, as it can lead to potential unautho [truncated]