YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0034

Register entry

FastChat server-side request forgery at POST /worker_generate_stream, found by Vulnhuntr

CVE
CVE-2024-10044
Project
lm-sys/FastChat
Finder
Vulnhuntr
Autonomy
LLM with Jedi static parsing, Python only; findings routed through huntr
Evidence tier
Claim outside the record
Assigner
@huntr_ai
Severity
9.3 Critical (CVSS 3.1)
Bounty
huntr.com; amount unpublished
Confidence
CONFIRMED

What happened

A server-side request forgery at POST /worker_generate_stream in lm-sys/FastChat, assigned by huntr with an empty credits array, listed in the Vulnhuntr README under "World's first autonomous AI-discovered 0day vulnerabilities". Product, class, date and CVSS reproduce at the record; the affected version numbers in circulation trace to huntr pages this desk has not opened.

Credit as recorded: credits array empty; attribution in the Vulnhuntr README. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026