Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-85695: FastChat lets strangers add fake workers to steal data

CVE-2026-85695 · published today
Summary

FastChat lets anyone add a new helper program without proving who they are. An attacker can register a fake helper that pretends to be a real AI model, capture users' questions, images and answers, and even scan other computers inside your network. Fix it by requiring login for adding helpers, installing the latest update, and limiting network access to trusted machines.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
lm-sys fastchat <= 0.2.36
Original advisory text
FastChat Unauthenticated Worker Registration SSRF and Model Spoofing
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
Severity
9.3 Critical
CVSS 3.1: 9.4 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85695 · MITRE
Monitor software like this
Free during beta