Lm Sys develops FastChat, an open-source conversational AI platform that has gained prominence in the machine-learning research and deployment community. The vendor's vulnerability portfolio remains modest and centered on this single product, reflecting its focused scope within the rapidly evolving generative-AI application landscape. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lm Sys over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5760CRITICAL SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat template | Apr 20, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-7304CRITICAL SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded vi | May 18, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-7301CRITICAL SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when ex | May 18, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-7302CRITICAL SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process ha | May 18, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-3059CRITICAL SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without | Mar 12, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-3060CRITICAL SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pic | Mar 12, 2026 | 9.8 | 33 | NO | NO |
CVE-2024-10044CRITICAL A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6 | Dec 30, 2024 | 9.3 | 26 | NO | NO |
CVE-2026-10775MEDIUM A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes | Jun 3, 2026 | 5.3 | 25 | NO | NO |
CVE-2024-10908MEDIUM An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This | Mar 20, 2025 | 6.1 | 24 | NO | YES |
CVE-2024-10907HIGH In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed mul | Mar 20, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lm Sys.
Media articles that mention a CVE ID that affects a product developed by Lm Sys — matched by CVE ID, not by vendor name.