← Back

CVE-2024-11603

nvd nist
Published: Mar 20, 2025Modified: Jul 29, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: security@huntr.dev (Secondary)

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS metadata endpoint, potentially exposing sensitive data and compromising internal servers.

Affected (1)

Products: Lm Sys: Fastchat
1 product
Fastchat
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.2.36

References (1)

Source: security@huntr.dev
ExploitThird Party Advisory

Timeline

No history available yet.