A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.
CVE ID: CVE-2024-12376
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor: lm-sys
Product: lm-sys/fastchat
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 12.24% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)