Deserialization Vulnerability in lm-sys FastChat Product
CVE-2025-3677

4.8MEDIUM

Key Information:

Vendor
Lm-sys
Status
Fastchat
Vendor
CVE Published:
16 April 2025

Summary

A deserialization vulnerability has been discovered in lm-sys FastChat that affects the apply_delta_low_cpu_mem function within the file fastchat/model/apply_delta.py. Exploiting this vulnerability may allow attackers to manipulate data processed by the function, leading to potential security risks. This issue necessitates local access to the affected system, suggesting that physical or network proximity is essential for successful exploitation. Users of lm-sys FastChat should apply mitigations to prevent unauthorized access and ensure system integrity.

Affected Version(s)

fastchat 0.2.0

fastchat 0.2.1

fastchat 0.2.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ybdesire (VulDB User)
.