PT-2026-60247 · Git+1 · Gpustack
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GPUStack versions prior to 2.2.1
Description
An unauthenticated information disclosure issue allows attackers to access sensitive inference logs and modify worker configuration. This is achieved by exploiting the unprotected '/serveLogs' and '/debug' endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, change log levels, and read memory profiling data without authentication.
Recommendations
Update to the version containing commit 4e20551.
Restrict access to the '/serveLogs' and '/debug' endpoints to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpustack