Authentication Bypass Vulnerability in FastChat by LM Systems
CVE-2026-85695
9.3CRITICAL
What is CVE-2026-85695?
FastChat contains an authentication bypass vulnerability within the /register_worker endpoint, potentially enabling unauthenticated attackers to register arbitrary worker addresses. This flaw allows for server-side request forgery attacks, where malicious workers can be registered under victim model names. As a result, attackers may intercept user data, including prompts, images, and responses, or they could probe internal network ports within the worker mesh, leading to further security risks.
Affected Version(s)
FastChat 0 <= 0.2.36
