Executive brief
SUSE Rancher AI Agent is a tool used to integrate artificial intelligence capabilities into the Rancher container management platform. A security flaw exists where, if the system is manually set to 'debug' mode, it may record sensitive information like API keys and private AI conversation data into its log files. This could allow an attacker with access to the logs to steal credentials and gain unauthorized access to connected AI services or sensitive business data.
Technical details
An information disclosure vulnerability (CWE-215) exists in SUSE Rancher AI Agent when the logging level is explicitly set to DEBUG. In this non-default configuration, the application fails to sanitize sensitive data, leading to the recording of LLM API keys and full Model Context Protocol (MCP) responses in plaintext log files. The root cause involves overly verbose logging in the 'openai._base_client' and 'Mcp.client.streamable_http' libraries, as well as insecure log statements during system setting modifications. While the SUSE CVSS 4.0 score suggests a local attack vector requiring high privileges, the GitHub advisory notes a network-based vector with high complexity. Attackers with access to log archives or centralized logging systems can retrieve these credentials to compromise integrated external services. The issue is fixed in version 1.0.2 by suppressing external library debug logs and removing the insecure log statements.
Affected products
- SUSE Rancher AI Agent >=1.0.0, <1.0.2
Timeline
- 2026-05-27: advisory: GitHub advisory published by maintainers
- 2026-07-06: disclosed: CVE published in NVD