PT-2026-33714 · Lmsys · Fastchat
Eric-F
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-6608
CVSS v2.0
5.0
Medium
| AV:N/AC:L/Au:N/C:N/I:P/A:N |
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio block arena named.py, but three other files were missed.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastchat