PT-2026-33657 · Unknown · Serge-Chat

Eric-A

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6588

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions serge-chat versions prior to 1.4TB
Description A flaw in the Model API Endpoint allows remote attackers to bypass authentication. This issue exists within the download model and delete model functions located in the 'api/src/serge/routers/model.py' file. Exploitation of this weakness can lead to unauthorized actions, including the deletion of models, and has been observed in real-world incidents.
Recommendations Update to a version later than 1.4TB. As a temporary workaround, restrict access to the download model and delete model functions in the Model API Endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-6588

Affected Products

Serge-Chat