A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-6588 is a missing authentication vulnerability in Serge Chat versions up to 1.4TB affecting the Model API Endpoint's download_model and delete_model functions. Remote attackers can exploit this weakness without credentials to manipulate model operations, with public exploits already available.
يؤثر هذا الضعف على وظائف تحميل وحذف النموذج في واجهة برمجة التطبيقات الخاصة بـ Serge Chat. يمكن للمهاجمين البعيدين استغلال هذا الضعف دون الحاجة إلى بيانات اعتماد صحيحة للوصول إلى عمليات إدارة النموذج.
A missing authentication flaw exists in Serge Chat up to version 1.4TB in the Model API Endpoint functions. Attackers can remotely exploit this vulnerability to download or delete models without proper authentication credentials.
Upgrade Serge Chat to a patched version beyond 1.4TB immediately. Implement network-level access controls to restrict API endpoint access. Deploy Web Application Firewall (WAF) rules to monitor and block unauthorized model download/delete requests. Enable API authentication mechanisms and implement rate limiting on model operations.
قم بترقية Serge Chat إلى إصدار مصحح فوراً. طبق عناصر تحكم في الوصول على مستوى الشبكة لتقييد الوصول إلى نقطة النهاية. استخدم جدار حماية تطبيقات الويب لمراقبة الطلبات غير المصرح بها. فعّل آليات المصادقة وحدد معدل الطلبات على عمليات النموذج.