Browse all 9 CVE security advisories affecting lm-sys. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Lm-sys develops open-source web application frameworks primarily used for building dynamic websites and APIs. Historically, the project has been vulnerable to multiple remote code execution flaws, cross-site scripting (XSS) vulnerabilities, and privilege escalation issues, accounting for its nine recorded CVEs. Security researchers have identified recurring problems in input validation and access control mechanisms. While no major public security incidents have been documented, the consistent pattern of vulnerabilities suggests developers should implement strict input sanitization and proper authentication controls when using this framework in production environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-10912 | Denial of Service in lm-sys/fastchat — lm-sys/fastchat CWE-400 | 7.5 | - | 2025-03-20 |
| CVE-2024-12376 | Server Side Request Forgery in lm-sys/fastchat — lm-sys/fastchat CWE-918 | 7.5 | - | 2025-03-20 |
| CVE-2024-10907 | Denial of Service (DoS) via Multipart Boundary in lm-sys/fastchat — lm-sys/fastchat CWE-835 | 7.5 | - | 2025-03-20 |
| CVE-2024-11603 | Server-Side Request Forgery in lm-sys/fastchat — lm-sys/fastchat CWE-918 | 7.5 | - | 2025-03-20 |
| CVE-2024-10908 | Open Redirect in lm-sys/fastchat — lm-sys/fastchat CWE-601 | 6.1 | - | 2025-03-20 |
| CVE-2024-10044 | SSRF in POST /worker_generate_stream API endpoint in lm-sys/fastchat — lm-sys/fastchat CWE-918 | 9.8 | - | 2024-12-30 |
This page lists every published CVE security advisory associated with lm-sys. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.