CVE-2026-54457
7.7TensorZero · tensorzero
TensorZero contains vulnerabilities involving server side request forgery and improper file access, which could allow external parties to access restricted directories.
Executive summary
A high severity vulnerability in the TensorZero platform permits unauthorized file access and server side request forgery, potentially exposing sensitive system resources.
Vulnerability
This vulnerability involves improper handling of files and directories alongside server side request forgery, allowing an attacker with low privileges to interact with internal resources or access sensitive paths.
Business impact
Successful exploitation allows an attacker to bypass security boundaries, potentially leading to unauthorized disclosure of sensitive data or internal system interactions. Given the CVSS score of 7.7, this issue represents a significant risk to the security posture of LLMOps infrastructure. Compromise could result in the exposure of internal configuration files or the use of the platform as a proxy for further network attacks.
Remediation
Immediate Action: Update the TensorZero package to version 2026.6.0 or later to apply the necessary security fixes.
Proactive Monitoring: Monitor network traffic originating from the TensorZero server to identify suspicious requests directed toward internal network resources.
Compensating Controls: Implement strict egress filtering on the server hosting TensorZero to prevent unauthorized internal network communication resulting from SSRF.
Exploitation status
Public Exploit Available: No (no confirmed public exploit)
Analyst recommendation
Organizations utilizing TensorZero must prioritize updating to version 2026.6.0 immediately. Failure to address these vulnerabilities leaves the platform exposed to potential unauthorized data access and internal network probing.