Skip to content
FastChatGHSA-77cj-rv5x-v6r2

FastChat open redirect vulnerability

Medium6.1CVE-2024-10908 · Published Mar 20, 2025 · updated Jul 7, 2026

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

GitHub advisory

Affected versions

PackageAffectedFixed in
fschat
PyPI
<= 0.2.36No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-601
Also known as
CVE-2024-10908, PYSEC-2026-1394

More FastChat advisories

All FastChat
Advisory
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
Medium5.3Apr 20
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
Medium5.3Apr 20
FastChat Server-Side Request Forgery vulnerability
High7.5Mar 20, 2025
FastChat Server-Side Request Forgery vulnerability
High7.5Mar 20, 2025
FastChat Denial of Service vulnerability
High7.5Mar 20, 2025
FastChat Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.