PT-2026-33657 · Unknown · Serge-Chat
Eric-A
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6588
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
serge-chat versions prior to 1.4TB
Description
A flaw in the Model API Endpoint allows remote attackers to bypass authentication. This issue exists within the
download model and delete model functions located in the 'api/src/serge/routers/model.py' file. Exploitation of this weakness can lead to unauthorized actions, including the deletion of models, and has been observed in real-world incidents.Recommendations
Update to a version later than 1.4TB.
As a temporary workaround, restrict access to the
download model and delete model functions in the Model API Endpoint to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Serge-Chat