CVE-2024-12376

HIGH

lm-sys fastchat - Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0044
EPSS Percentile 63.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
lm-sys/fastchat 2024-10-05
pypi/fschat 0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026