PyPI: fschat

CVE-2024-10908

Safety vulnerability ID: SFTY-20250320-15555

Safety legacy ID: pyup.io-76278

Affected versions of the lm-sys FastChat package are vulnerable to Open Redirect. The application fails to properly validate and sanitize user-supplied URL parameters, leading to unauthorized redirection. A remote unauthenticated attacker can exploit this vulnerability by crafting a malicious URL with a specially crafted redirect parameter, resulting in users being redirected to arbitrary external websites, which can facilitate phishing attacks, malware distribution, and credential theft.

Created at: Nov 5, 2025Updated at: Nov 5, 2025

Overview

FastChat open redirect vulnerability

Advisory

Affected versions of the lm-sys FastChat package are vulnerable to Open Redirect. The application fails to properly validate and sanitize user-supplied URL parameters, leading to unauthorized redirection. A remote unauthenticated attacker can exploit this vulnerability by crafting a malicious URL with a specially crafted redirect parameter, resulting in users being redirected to arbitrary external websites, which can facilitate phishing attacks, malware distribution, and credential theft.

Affected Package

Affecting fschat package, versions
<=0.2.36

Also affects

---

How to Fix

We recommend updating fschat to the latest non-vulnerable version.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more