In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cleartext Storage of Sensitive Information vulnerabilities in an interactive lesson.
Start learningUpgrade github.com/kserve/kserve/pkg/credentials/hf to version 0.16.0-rc0 or higher.
Affected versions of this package are vulnerable to Cleartext Storage of Sensitive Information due to the Hugging Face HF_TOKEN. Because the token is exposed directly in environment variables, any user or process with access to container metadata, logs, or runtime inspection tools can obtain the secret, allowing unauthorized access to protected Hugging Face resources.