CVE-2026-108857 | Hugging Face Text Embeddings Inference up to 1.9.4 Router Args api_key missing encryption

SecurityVulns

A vulnerability has been found in Hugging Face Text Embeddings Inference up to 1.9.4 and classified as problematic. This affects an unknown part of the component Router Args. This manipulation of the argument api_key causes missing encryption of sensitive data.

This vulnerability is handled as CVE-2026-108857. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More