Skip to content
FastChatGHSA-g44m-hpf4-vmrp

FastChat Server-Side Request Forgery vulnerability

High7.5CVE-2024-12376 · Published Mar 20, 2025 · updated Jul 7, 2026

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.

GitHub advisory

Affected versions

PackageAffectedFixed in
fschat
PyPI
<= 0.2.36No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918
Also known as
CVE-2024-12376, PYSEC-2026-1396

More FastChat advisories

All FastChat
Advisory
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
Medium5.3Apr 20
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
Medium5.3Apr 20
FastChat Server-Side Request Forgery vulnerability
High7.5Mar 20, 2025
FastChat open redirect vulnerability
Medium6.1Mar 20, 2025
FastChat Denial of Service vulnerability
High7.5Mar 20, 2025
FastChat Uncontrolled Resource Consumption vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.