PT-2026-85581 · Lmsys · Fastchat

·

CVE-2026-85695

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
FastChat contains an authentication bypass vulnerability in the /register worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85695

Affected Products

Fastchat