# CVE-2026-54457

## Summary

- **CVE ID:** CVE-2026-54457
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-552, CWE-918
- **Published:** Aug 21, 2026
- **Last Modified:** Aug 25, 2026

## Description

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gateway filesystem to be read, including credential files. Selecting the s3_compatible storage type causes outbound object-storage requests to attacker-chosen internal or cloud-metadata endpoints. Exploitation requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This issue is fixed in version 2026.6.0.

## Affected Products

- tensorzero — tensorzero (< 2026.6.0)

## References

- [CNA](https://github.com/tensorzero/tensorzero/security/advisories/GHSA-824w-x939-6cmc)
- [CNA](https://github.com/tensorzero/tensorzero/commit/0abbc838bae3394fe7491dad7009670d4e3b6cf8)
- [CNA](https://github.com/tensorzero/tensorzero/releases/tag/2026.6.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._