Medium severity6.1NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-10908
CVE-2024-10908
Description
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fschatPyPI | <= 0.2.36 | — |
Affected products
3Patches
Vulnerability mechanics
References
3- huntr.com/bounties/61f5e725-5579-4d08-8a88-e4ba04e6d1f2nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-77cj-rv5x-v6r2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-10908ghsaADVISORY
News mentions
0No linked articles in our index yet.