mediumCVSS 5.3Vulnerability

CVE-2026-6608

A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio_block_arena_named.py, but three other files were missed.

Properties

severity
medium
summary
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
epss_score
0.00308
cvss_score
5.3
ghsa_published
2026-04-20T06:31:28Z
source_url
https://github.com/advisories/GHSA-f3q6-69f3-vwch
ghsa_updated
2026-04-23T14:29:57Z
ghsa_id
GHSA-f3q6-69f3-vwch
cve_id
CVE-2026-6608
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.231

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]pip/fschat

AFFECTS (1)

[Software]pip/fschat

HAS_WEAKNESS (1)

[Weakness]Always-Incorrect Control Flow Implementation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph