CVE-2026-6608

A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio_block_arena_named.py, but three other files were missed.
Configurations

No configuration.

History

20 Apr 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-20 06:16

Updated : 2026-04-22 20:22


NVD link : CVE-2026-6608

Mitre link : CVE-2026-6608

CVE.ORG link : CVE-2026-6608


JSON object : View

Products Affected

No product.

CWE
CWE-670

Always-Incorrect Control Flow Implementation