CVE-2024-11603

A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS metadata endpoint, potentially exposing sensitive data and compromising internal servers.
References
Link Resource
https://huntr.com/bounties/89f1158d-4a75-4000-a1bd-f82dd1a62bff Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:lm-sys:fastchat:0.2.36:*:*:*:*:*:*:*

History

29 Jul 2025, 19:36

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Server-Side Request Forgery (SSRF) en lm-sys/fastchat versión 0.2.36. La vulnerabilidad se presenta en el endpoint `/queue/join?`, donde una validación insuficiente del parámetro path permite a un atacante enviar solicitudes manipuladas. Esto puede provocar acceso no autorizado a las redes internas o al endpoint de metadatos de AWS, lo que podría exponer datos confidenciales y comprometer los servidores internos.
References () https://huntr.com/bounties/89f1158d-4a75-4000-a1bd-f82dd1a62bff - () https://huntr.com/bounties/89f1158d-4a75-4000-a1bd-f82dd1a62bff - Exploit, Third Party Advisory
First Time Lm-sys
Lm-sys fastchat
CPE cpe:2.3:a:lm-sys:fastchat:0.2.36:*:*:*:*:*:*:*

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-29 19:36


NVD link : CVE-2024-11603

Mitre link : CVE-2024-11603

CVE.ORG link : CVE-2024-11603


JSON object : View

Products Affected

lm-sys

  • fastchat
CWE
CWE-918

Server-Side Request Forgery (SSRF)