Impact
The flaw is a missing authentication check in the delete_model API of serge-chat’s serge component. An unauthenticated user can send a delete request and remove a stored model. Because the endpoint is reachable over the network and the exploit is publicly available, attackers can execute this action from anywhere, leading to loss of model data and disruption of the chatbot’s knowledge base.
Affected Systems
All installations of serge-chat serge up to version 1.4TB that have not applied the vendor’s fix are susceptible to unauthenticated model deletion.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is classified as medium severity. The remote attack surface and lack of authentication make exploitation straightforward, though EPSS data is not available and the flaw is not listed in CISA’s KEV catalog. The public availability of the exploit increases the probability that a real attacker will target affected systems.
OpenCVE Enrichment