CVE-2024-10908: Lm-Sys Fastchat

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

Affected products

  • Lm-Sys Fastchat: version 0.2.36 only

Published 2025-03-20. Last modified 2026-06-17.