Safety vulnerability ID: 76278
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the lm-sys FastChat package are vulnerable to Open Redirect. The application fails to properly validate and sanitize user-supplied URL parameters, leading to unauthorized redirection. A remote unauthenticated attacker can exploit this vulnerability by crafting a malicious URL with a specially crafted redirect parameter, resulting in users being redirected to arbitrary external websites, which can facilitate phishing attacks, malware distribution, and credential theft.
Latest version: 0.2.36
An open platform for training, serving, and evaluating large language model based chatbots.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application