Safety vulnerability ID: 76265
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the lm-sys FastChat package are vulnerable to Server-Side Request Forgery (SSRF). The web server functionality fails to properly validate and sanitize user-supplied URL parameters, leading to unauthorized access to internal resources. An unauthenticated attacker can exploit this vulnerability by crafting malicious requests to internal endpoints such as the AWS EC2 Instance Metadata Service, resulting in the exposure of sensitive credentials, including AWS IAM access keys, secret keys, and session tokens, potentially leading to full cloud infrastructure compromise.
Latest version: 0.2.36
An open platform for training, serving, and evaluating large language model based chatbots.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application