FastChatGHSA-g44m-hpf4-vmrp
FastChat Server-Side Request Forgery vulnerability
High7.5CVE-2024-12376 · Published Mar 20, 2025 · updated Jul 7, 2026
A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| fschat PyPI | <= 0.2.36 | No fix yet |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2024-12376, PYSEC-2026-1396
More FastChat advisories
All FastChat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 20 | FastChat has a Content Moderation Bypass via Arena Side-by-Side Views | Medium5.3 | No fix yet |
| Apr 20 | FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426) | Medium5.3 | No fix yet |
| Mar 202025 | FastChat Server-Side Request Forgery vulnerability | High7.5 | No fix yet |
| Mar 202025 | FastChat open redirect vulnerability | Medium6.1 | No fix yet |
| Mar 202025 | FastChat Denial of Service vulnerability | High7.5 | No fix yet |
| Mar 202025 | FastChat Uncontrolled Resource Consumption vulnerability | High7.5 | No fix yet |