{"id":"CVE-2026-54457","summary":"TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint","details":"TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gateway filesystem to be read, including credential files. Selecting the s3_compatible storage type causes outbound object-storage requests to attacker-chosen internal or cloud-metadata endpoints. Exploitation requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This issue is fixed in version 2026.6.0.","aliases":["GHSA-824w-x939-6cmc","PYSEC-2026-3541"],"modified":"2026-08-23T03:53:39.434761551Z","published":"2026-08-21T20:34:03.632Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-552","CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54457.json"},"references":[{"type":"WEB","url":"https://github.com/tensorzero/tensorzero/releases/tag/2026.6.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54457.json"},{"type":"ADVISORY","url":"https://github.com/tensorzero/tensorzero/security/advisories/GHSA-824w-x939-6cmc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54457"},{"type":"FIX","url":"https://github.com/tensorzero/tensorzero/commit/0abbc838bae3394fe7491dad7009670d4e3b6cf8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tensorzero/tensorzero","events":[{"introduced":"0"},{"fixed":"0abbc838bae3394fe7491dad7009670d4e3b6cf8"},{"fixed":"62eb8f63e8ec62018d70420dbf1a8c5d1c026315"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2026.6.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2026.5.2","2026.5.1","2026.5.0","2026.4.1","2026.4.0","2026.3.4","2026.3.3","2026.3.2","2026.3.1","2026.3.0","2026.2.2","2026.2.1","2026.2.0","2026.1.8","2026.1.7","2026.1.6","2026.1.5","2026.1.2","2026.1.1","2026.1.0","2025.12.6","2025.12.5","2025.12.4","2025.12.3","2025.12.2","2025.12.1","2025.12.0","2025.11.5","2025.11.6","2025.11.4","2025.11.3","2025.11.2","2025.11.1","2025.11.0","2025.10.9","2025.10.7","2025.10.6","2025.10.5","2025.10.4","2025.10.3","2025.10.2","2025.10.1","2025.10.0","2025.9.6","2025.9.5","2025.9.4","2025.9.3","2025.9.1","2025.9.0","2025.8.5","2025.8.4","2025.8.3","2025.8.2","2025.8.1","2025.8.0","2025.7.5","2025.7.4","2025.7.3","2025.7.2","2025.7.1","2025.7.0","2025.6.3","2025.6.2","2025.6.1","2025.6.0","2025.5.9","2025.5.8","2025.5.7","2025.5.6","2025.5.5","2025.5.4","2025.5.3","2025.5.2","2025.5.1","2025.5.0","2025.4.8","2025.4.7","2025.4.6","2025.4.5","2025.4.4","2025.4.3","2025.4.2","2025.04.1","2025.04.0","2025.03.4","2025.03.3","2025.03.2","2025.03.1","2025.03.0","2025.02.6","2025.02.5","2025.02.4","2025.02.3","2025.02.2","2025.02.1","2025.02.0","2025.01.9","2025.01.8","2025.01.7","2025.01.6","2025.01.5","2025.01.4","2025.01.3","2025.01.2","2025.01.1","2025.01.0","2024.12.3","2024.12.2","2024.12.1","2024.12.0","2024.11.4","2024.11.3","2024.11.2","2024.11.1","2024.11.0","2024.10.1","2024.10.0","2024.09.3","2024.09.2","2024.09.1","2024.09.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54457.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}