Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lm Sys

First CVE: Dec 30, 2024Active for: 2 yearsTotal CVEs: 19

Lm Sys develops FastChat, an open-source conversational AI platform that has gained prominence in the machine-learning research and deployment community. The vendor's vulnerability portfolio remains modest and centered on this single product, reflecting its focused scope within the rapidly evolving generative-AI application landscape. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 86% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lm Sys over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2024
18 months ago
Most Recent CVE
Jun 3, 2026
51 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-5760CRITICAL
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat template
Apr 20, 20269.841NONO
CVE-2026-7304CRITICAL
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded vi
May 18, 20269.838NONO
CVE-2026-7301CRITICAL
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when ex
May 18, 20269.838NONO
CVE-2026-7302CRITICAL
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process ha
May 18, 20269.135NONO
CVE-2026-3059CRITICAL
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without
Mar 12, 20269.834NONO
CVE-2026-3060CRITICAL
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pic
Mar 12, 20269.833NONO
CVE-2024-10044CRITICAL
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6
Dec 30, 20249.326NONO
CVE-2026-10775MEDIUM
A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes
Jun 3, 20265.325NONO
CVE-2024-10908MEDIUM
An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This
Mar 20, 20256.124NOYES
CVE-2024-10907HIGH
In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed mul
Mar 20, 20257.522NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
15%
31%
54%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None12 (92.3%)
Unknown0 (0.0%)
Required1 (7.7%)
Privileges Required
Low1 (7.7%)
High0 (0.0%)
None12 (92.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lm Sys.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lm Sys — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lm Sys's Products

View all 3 CNAs →

Top CWEs