CVE-2026-54457: Tensorzero
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gateway filesystem to be read, including credential files. Selecting the s3_compatible storage type causes outbound object-storage requests to attacker-chosen internal or cloud-metadata endpoints. Exploitation requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This issue is fixed in version 2026.6.0.
Affected products
- Tensorzero Tensorzero: before 2026.6.0 (fixed in 2026.6.0)
Published 2026-08-21. Last modified 2026-09-11.