GPUStack Unauthenticated Information Disclosure via Worker Endpoints
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker configuration by exploiting unprotected /serveLogs and /debug endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, change log levels, and read memory profiling data without any authentication.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
gpustack · gpustackpublic PoCs found — 1
cve_referencegithub.com/gpustack/gpustack/issues/5836unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.