CVE-2024-10908Medium· 6.1▾ TwilightPoC availableFastChat open redirect vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
Nuclei ×1
0.8% → 0.8%
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
fschat <= 0.2.36Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6608Medium· 5.3FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6607Medium· 5.3FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
CVE-2024-10907High· 7.5FastChat Uncontrolled Resource Consumption vulnerability
CVE-2024-11603High· 7.5FastChat Server-Side Request Forgery vulnerability
CVE-2024-12376High· 7.5FastChat Server-Side Request Forgery vulnerability
CVE-2024-10912High· 7.5FastChat Denial of Service vulnerability