CVE-2024-11603High· 7.5▾ TwilightFastChat Server-Side Request Forgery vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the /queue/join? endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS metadata endpoint, potentially exposing sensitive data and compromising internal servers.
fschat <= 0.2.36Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6608Medium· 5.3FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
CVE-2026-6607Medium· 5.3FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
CVE-2024-10907High· 7.5FastChat Uncontrolled Resource Consumption vulnerability
CVE-2024-12376High· 7.5FastChat Server-Side Request Forgery vulnerability
CVE-2024-10912High· 7.5FastChat Denial of Service vulnerability
CVE-2024-10908Medium· 6.1FastChat open redirect vulnerability