Back to Database
Status published
Medium
CVE-2024-10908
Open Redirect in lm-sys/fastchat
Vulnerability Description
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10908
Credits & Attribution
No credits recorded in the NVD database.
More from lm-sys
View All →CVE-2025-3677
lm-sys fastchat apply_delta.py apply_delta_low_cpu_mem deserialization
Medium
4.8
CVE-2024-12376
Server Side Request Forgery in lm-sys/fastchat
High
7.5
CVE-2024-11603
Server-Side Request Forgery in lm-sys/fastchat
High
7.5
CVE-2024-10912
Denial of Service in lm-sys/fastchat
High
7.5
CVE-2024-10907
Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat
High
7.5
Affected Vendor
lm-sys
View all reports →Affected Software
lm-sys/fastchat
Vulnerable Versions:
unspecified
Timeline
Official Publish:
March 20th, 2025
Last Modified:
March 20th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N