CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-12376: Server Side Request Forgery in lm-sys/fastchat

7.5 CVSS

Description

A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.

Classification

CVE ID: CVE-2024-12376

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem Types

CWE-918 Server-Side Request Forgery (SSRF)

Affected Products

Vendor: lm-sys

Product: lm-sys/fastchat

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 12.24% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-12376
https://huntr.com/bounties/c9cc3f28-ee9f-4d2d-9ee5-8c6455a11892

Timeline