---
id: CVE-2026-6608
aliases:
  - GHSA-f3q6-69f3-vwch
  - PYSEC-2026-2485
title: FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
summary: FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
vendor: fschat
product: fschat
ecosystem: pip
affected:
  - fschat <= 0.2.36
published: '2026-04-20'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-f3q6-69f3-vwch'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6608'
  - url: 'https://github.com/lm-sys/FastChat/issues/3834'
  - url: 'https://gist.github.com/YLChen-007/e45039d23e698222d887ee09735d9d36'
  - url: 'https://github.com/lm-sys/FastChat'
  - url: 'https://vuldb.com/submit/792228'
  - url: 'https://vuldb.com/vuln/358243'
  - url: 'https://vuldb.com/vuln/358243/cti'
tags:
  - osv
  - pip
epss: 0.00511
epssPercentile: 0.4099
ingestedAt: '2026-07-13T18:57:57.094Z'
---

## Overview

A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The exploit is now public and may be used. The root cause was fixed in commit 34eca62 for gradio_block_arena_named.py, but three other files were missed.

## Affected packages

- `fschat <= 0.2.36`

## Remediation

Refer to the advisory for the patched release.
