PT-2026-85581 · Lmsys · Fastchat

·

CVE-2026-85695

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

CVSS v3.1

9.4

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
FastChat contains an authentication bypass vulnerability in the /register worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-85695

Produtos afetados

Fastchat