CVE-2026-108754 | tbphp GPT-Load up to 1.4.11 Gin Logger middleware /data/logs/app.log extractAuthKey key missing encryption

SecurityVulns

A vulnerability was found in tbphp GPT-Load up to 1.4.11 and classified as problematic. Affected by this vulnerability is the function extractAuthKey of the file /data/logs/app.log of the component Gin Logger middleware. The manipulation of the argument key results in missing encryption of sensitive data.

This vulnerability was named CVE-2026-108754. The attack needs to be approached locally. There is no available exploit.VulDB Recent EntriesRead More