📦 Fastchat

by Lm Sys

🔍 What is Fastchat?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10044

CRITICAL CVSS 9.3 Dec 30, 2024

This SSRF vulnerability in FastChat's Controller API Server allows attackers to make the server send unauthorized requests to internal or external systems using the server's credentials. Attackers can...

CVE-2024-12376

HIGH CVSS 7.5 Mar 20, 2025

A Server-Side Request Forgery (SSRF) vulnerability in lm-sys/fastchat web server allows attackers to make the server send requests to internal resources, potentially accessing sensitive data like AWS ...

CVE-2024-11603

HIGH CVSS 7.5 Mar 20, 2025

A Server-Side Request Forgery (SSRF) vulnerability in lm-sys/fastchat version 0.2.36 allows attackers to send crafted requests through the /queue/join? endpoint, potentially accessing internal network...

CVE-2024-10907

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability in lm-sys/fastchat v0.2.36 allows unauthenticated attackers to cause denial of service by sending malformed multipart requests with excessive characters in boundary fields. The serv...

CVE-2024-10912

HIGH CVSS 7.5 Mar 20, 2025

A Denial of Service (DoS) vulnerability in lm-sys/fastchat version 0.2.36 allows attackers to crash the server by uploading a file with an excessively large filename. This affects users of fastchat's ...

CVE-2024-10908

MEDIUM CVSS 6.1 Mar 20, 2025

An open redirect vulnerability in lm-sys/fastchat v0.2.36 allows attackers to redirect users to malicious websites via crafted URLs. This affects all users accessing vulnerable FastChat instances, ena...