PT-2026-33714 · Lmsys · Fastchat

Eric-F

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6608

CVSS v2.0

5.0

Medium

AV:N/AC:L/Au:N/C:N/I:P/A:N
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio block arena named.py, but three other files were missed.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-6608

Affected Products

Fastchat