fastchatGHSA-f3q6-69f3-vwch
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
Medium5.3CVE-2026-6608 · Published Apr 20, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| fschat PyPI | <= 0.2.36 | No fix yet |
Details and references
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio_block_arena_named.py, but three other files were missed.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-670
- Also known as
- CVE-2026-6608, PYSEC-2026-2485
More fastchat advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 20 | FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426) CVE-2026-6607Medium5.3no fix yet | Medium5.3 | No fix yet |
| Mar 202025 | FastChat Server-Side Request Forgery vulnerability CVE-2024-12376High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | FastChat Server-Side Request Forgery vulnerability CVE-2024-11603High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | FastChat open redirect vulnerability CVE-2024-10908Medium6.1no fix yet | Medium6.1 | No fix yet |
| Mar 202025 | FastChat Denial of Service vulnerability CVE-2024-10912High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | FastChat Uncontrolled Resource Consumption vulnerability CVE-2024-10907High7.5no fix yet | High7.5 | No fix yet |