Description
A vulnerability classified as critical was found in lm-sys fastchat up to 0.2.36. This vulnerability affects the function split_files/apply_delta_low_cpu_mem of the file fastchat/model/apply_delta.py. The manipulation leads to deserialization. An attack has to be approached locally.
References (4)
Core 4
Core References
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.304966
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.304966
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.552755
Issue Tracking issue-tracking
https://github.com/lm-sys/FastChat/issues/3713
Scores
CVSS v3
5.3
EPSS
0.0017
EPSS Percentile
6.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
CWE-502
Status
published
Products (37)
lm-sys/fastchat
0.2.0
lm-sys/fastchat
0.2.1
lm-sys/fastchat
0.2.10
lm-sys/fastchat
0.2.11
lm-sys/fastchat
0.2.12
lm-sys/fastchat
0.2.13
lm-sys/fastchat
0.2.14
lm-sys/fastchat
0.2.15
lm-sys/fastchat
0.2.16
lm-sys/fastchat
0.2.17
... and 27 more
Published
Apr 16, 2025
Tracked Since
Feb 18, 2026