Junglewise Threat Intelligence

CVE-2026-85695: FastChat authentication bypass in /register_worker endpoint

CVE-2026-85695 · Severity: critical · CVSS 9.4 · Published 2026-09-04

Executive brief

FastChat is an open platform for training, serving, and evaluating large language models that powers services handling millions of chat requests. An authentication bypass in the worker registration endpoint allows attackers to register malicious workers without credentials, enabling them to intercept user conversations, steal images and responses, or scan internal networks for vulnerabilities.

Technical details

The vulnerability is an authentication bypass in the /register_worker endpoint that fails to validate request credentials. Attackers can send unauthenticated requests to register arbitrary worker addresses under legitimate model names. This enables two primary attack vectors: (1) prompt injection and data interception—malicious workers receive user queries and can respond with adversarial outputs or exfiltrate sensitive information; (2) server-side request forgery (SSRF)—attackers probe internal network ports across the worker mesh. No authentication or special preconditions are required; the endpoint is directly network-accessible. Patches addressing this vulnerability are available in upstream FastChat releases.

Affected products

  • lm-sys FastChat prior to patched releases

Timeline

  • 2026-09-04: disclosed

References