CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-108858: LoRAX 0 through 0.12.1

Affected technology

LoRAX · 0 through 0.12.1
Predibase

Description’s affected range: through 0.12.1

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

Attackers with access to router logs or OTLP trace backends can recover other users' private-adapter tokens recorded through the instrumented GenerateParameters span field. Vendor/CNA’s CVSS 4.0 assessment (base score 6.8/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-532
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-108858.html