Labring Fastgpt vulnerabilities
33 known vulnerabilities affecting labring/fastgpt.
Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH11MEDIUM15LOW1
Vulnerabilities
Page 1 of 2
CVE-2026-42302P2CRITICALCVSS 9.8v>= 4.14.10, < 4.14.132026-05-08
CVE-2026-42302 [CRITICAL] CWE-306 CVE-2026-42302: FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-
FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The startup script entrypoint.sh initializes code-server with the --auth none flag and binds the service to all network interfaces (0.0.0.0:8080). This config
nvd
CVE-2026-40351P2CRITICALCVSS 9.8fixed in 4.14.9.52026-04-17
CVE-2026-40351 [CRITICAL] CWE-943 CVE-2026-40351: FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login en
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling logi
nvd
CVE-2026-34162P2CRITICALCVSS 10.0fixed in 4.14.9.52026-03-31
CVE-2026-34162 [CRITICAL] CWE-306 CVE-2026-34162: FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes a server-side HTTP request and
nvd
CVE-2025-49131P2CRITICALCVSS 9.9fixed in 4.9.112025-06-09
CVE-2025-49131 [CRITICAL] CWE-732 CVE-2025-49131: FastGPT is an open-source project that provides a platform for building, deploying, and operating AI
FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a specialized, isolated environment used by FastGPT to safely execute user-submitted or dynamically generated code in isolation. The sandbox before version 4.9.1
nvd
CVE-2026-33075P2HIGHCVSS 8.8≤ 4.14.8.32026-03-20
CVE-2026-33075 [HIGH] CWE-494 CVE-2026-33075: FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.
FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out code from the pull request author's fork, then builds a
nvd
CVE-2026-68929P2CRITICALCVSS 9.3v>= 4.14.10, < 4.14.29v>= 4.15.0, < 4.15.22026-08-28
CVE-2026-68929 [CRITICAL] CWE-306 CVE-2026-68929: FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result, an unauthenticated attacker who knows a victim team's shareId can tak
nvd
CVE-2026-61684P2HIGHCVSS 8.8v= 4.15.0-beta42026-07-15
CVE-2026-61684 [HIGH] CWE-798 CVE-2026-61684: FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse
FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official deployment templates. An unauthenticated attacker can self-sign an HS256 JW
nvd
CVE-2026-40352P3HIGHCVSS 8.8fixed in 4.14.9.52026-04-17
CVE-2026-40352 [HIGH] CWE-943 CVE-2026-40352: FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoin
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or ot
nvd
CVE-2026-44285P3HIGHCVSS 7.7fixed in 4.15.0-beta12026-05-29
CVE-2026-44285 [HIGH] CWE-918 CVE-2026-44285: FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploiting an incomplete fix in the dataset preview endpoin
nvd
CVE-2026-40252P3HIGHCVSS 8.1fixed in 4.14.10.42026-04-10
CVE-2026-40252 [HIGH] CWE-284 CVE-2026-40252: FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (I
FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams by supplying a foreign appId. While the API correctly validates the team token, it does not verify that the requested application belongs to the authenti
nvd
CVE-2026-50562P3CRITICALCVSS 9.3≤ 22ebfacbb43311e9b73294040ae0eb87390c6bba2026-07-15
CVE-2026-50562 [CRITICAL] CWE-266 CVE-2026-50562: FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by privileged workflow_run jobs in .github/workflows/preview-docs-push.y
nvd
CVE-2026-55418P3HIGHCVSS 8.6fixed in 4.15.0-beta52026-07-07
CVE-2026-55418 [HIGH] CWE-639 CVE-2026-55418: FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handl
FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to the caller's team. Because S3 object keys are global within the bucket and carry the tenant id o
nvd
CVE-2026-34163P3HIGHCVSS 7.7fixed in 4.14.9.52026-03-31
CVE-2026-34163 [HIGH] CWE-918 CVE-2026-34163: FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Pr
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept a user-supplied URL parameter and make server-side HTTP requests to it without validating whether the URL points to an internal/private network address.
nvd
CVE-2026-61644P3HIGHCVSS 7.7v>= 4.14.17, < 4.15.0-beta52026-07-15
CVE-2026-61644 [HIGH] CWE-863 CVE-2026-61644: FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId center-node lookup is not bound to that authorized context. A low-privileged tenant user can call the endpoint with valid attacker-ow
nvd
CVE-2026-54607P3HIGHCVSS 7.7fixed in 4.15.0-beta42026-07-07
CVE-2026-54607 [HIGH] CWE-918 CVE-2026-54607: FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI s
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer validates only the top-level URL before passing it to SwaggerParser.bundle, whose remote reference resolver fetches $ref URLs without FastGPT's internal-address guard and returns fetched content inline, allowing an authenticated team memb
nvd
CVE-2026-42345P3HIGHCVSS 7.7≤ 4.14.112026-05-08
CVE-2026-42345 [HIGH] CWE-918 CVE-2026-42345: FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress
FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a fullUrl.startsWith() check against a hardcoded list. This check can be bypassed using at least 7 different URL encoding techniques, all of which resolve to th
nvd
CVE-2026-54601P3MEDIUMCVSS 6.3v>= 4.14.17, < 4.15.0-beta42026-07-07
CVE-2026-54601 [MEDIUM] CWE-915 CVE-2026-54601: FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT a
FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in a way that persists a server-owned datasetId value from another tenant. This creates mixed dataset objects and downstream dataset, collection,
nvd
CVE-2026-61646P3MEDIUMCVSS 6.3fixed in 4.15.0-beta52026-07-15
CVE-2026-61646 [MEDIUM] CWE-918 CVE-2026-61646: FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF g
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to axios, and axios follows redirects by default. An authenticated workflow user can configure an HTTP request node to call an attacker-controlled public URL that redirects to clou
nvd
CVE-2026-54602P3HIGHCVSS 7.1fixed in 4.15.02026-07-07
CVE-2026-54602 [HIGH] CWE-639 CVE-2026-54602: FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRe
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without team scoping, allowing any authenticated user to read another team's prompts, retrieved RAG chunks, and completions if the requestId is known. This issue i
nvd
CVE-2026-44287P3MEDIUMCVSS 6.3fixed in 4.15.0-beta12026-05-29
CVE-2026-44287 [MEDIUM] CWE-94 CVE-2026-44287: FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at pr
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax accepts a block comment between import and (; the regex matches only ASCII whitespace, and the bytes /, *, *, / are not in t
nvd
1 / 2Next →