FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lm-sys
Lm-sys fastchat |
|
| Vendors & Products |
Lm-sys
Lm-sys fastchat |
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh. | |
| Title | FastChat Unauthenticated Worker Registration SSRF and Model Spoofing | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T14:32:38.104Z
Updated: 2026-09-04T15:05:18.305Z
Reserved: 2026-09-04T13:51:51.902Z
Link: CVE-2026-85695
Updated: 2026-09-04T15:05:08.828Z
Status : Deferred
Published: 2026-09-04T15:17:47.690
Modified: 2026-09-10T15:53:23.707
Link: CVE-2026-85695
No data.