Impact
FastChat suffers from an authentication bypass in the /register_worker endpoint, permitting attackers to register arbitrary worker addresses without credentials. This flaw allows server‑side request forgery (SSRF) and model‑spoofing attacks. An attacker can register malicious workers under legitimate model names and hijack user prompts, images, and replies, or probe internal network ports across the worker mesh. The vulnerability is classified as Missing Authentication and can lead to data interception and internal reconnaissance.
Affected Systems
Affected systems include FastChat from lm‑sys. The CNA data does not specify which releases are vulnerable; the issue was observed in repository commit lists but no exact version range is given, so any deployed FastChat instance remains at risk until a patched release is released.
Risk and Exploitability
A CVSS score of 9.3 places the flaw in the high‑severity range, and without an EPSS value, the exploitation probability remains unclear but the lack of authentication makes the attack path trivial. The vulnerability is not currently listed in the CISA KEV catalog, but the potential for widespread internal network discovery and data exfiltration makes timely remediation critical. Attackers can exploit the flaw by sending a crafted request to the vulnerable /register_worker endpoint from any host that can reach the FastChat service.
OpenCVE Enrichment