CVE-2026-85695: FastChat Unauthenticated Worker Registration SSRF and Model Spoofing

Published Sep 4, 2026
·
Updated

FastChat contains an authentication bypass vulnerability in the /registerworker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.

Affected Software

1 affected component
FastChat

Event History

Sep 4, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which FastChat deployments are exposed?

Deployments whose /register_worker endpoint is reachable by an unauthenticated attacker are exposed. The issue allows arbitrary worker addresses to be registered with the controller.

2

What can an attacker do after registering a malicious worker?

An attacker can register a worker under a victim model name and intercept user prompts, images, and responses routed to that model. They can also use registered worker addresses to induce server-side requests and probe internal network ports across the worker mesh.

3

Does exploitation require credentials or user interaction?

No. The provided severity vector identifies the issue as network-accessible with low attack complexity, no privileges required, and no user interaction required.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203