CVE-2024-10044
CRITICALlm-sys fastchat - Server-Side Request Forgery via POST /worker_generate_stream Endpoint
Title source: llmDescription
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6837d590b81cb03847c0b9de100765. This vulnerability allows attackers to exploit the victim controller API server's credentials to perform unauthorized web actions or access unauthorized web resources by combining it with the POST /register_worker endpoint.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/44633540-377d-4ac4-b3a3-c2d0fa19d0e6
Scores
CVSS v3
9.3
EPSS
0.0050
EPSS Percentile
39.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
lm-sys/fastchat
2024-09-23
Published
Dec 30, 2024
Tracked Since
Feb 18, 2026