cbcvebase.

Labring Fastgpt vulnerabilities

33 known vulnerabilities affecting labring/fastgpt.

Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH11MEDIUM15LOW1

Vulnerabilities

Page 2 of 2
CVE-2026-44284P3MEDIUMCVSS 6.3fixed in 4.14.172026-05-08
CVE-2026-44284 [MEDIUM] CWE-918 CVE-2026-44284: FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The direct MCP preview/run endpoints already rejected internal/private network URLs, but the MCP tool create/update endpoints could still save an internal MCP server URL. That stored URL could later be used by
nvd
CVE-2026-32128P3MEDIUMCVSS 6.3≤ 4.14.72026-03-11
CVE-2026-32128 [MEDIUM] CWE-184 CVE-2026-32128: FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-s FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes guardrails intended to prevent file writes (static detection + seccomp). These guardrails are bypassable by remapping stdout (fd 1) to an arbitrary writable file descriptor using fcntl. After remapping, writing via sys.stdout.write()
nvd
CVE-2026-84301P3MEDIUMCVSS 6.3fixed in 4.15.22026-09-22
CVE-2026-84301 [MEDIUM] CWE-918 CVE-2026-84301: FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4. FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a later HTTP connection performs an independent DNS lookup, creating a DNS rebinding window, allowing an attacker-con
nvd
CVE-2026-42343P3MEDIUMCVSS 6.3≤ 4.14.132026-05-08
CVE-2026-42343 [MEDIUM] CWE-400 CVE-2026-42343: FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service relies solely on an application-level soft limit (a 500ms polling interval) for memory management and lacks strict OS-level constraints such as cgroups or k
nvd
CVE-2026-61643P3MEDIUMCVSS 5.9v>= 4.14.17, < 4.15.0-beta52026-07-15
CVE-2026-61643 [MEDIUM] CWE-863 CVE-2026-61643: FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authentica FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's private HTTP toolset by using a crafted saved tool id such as http-/. The normal toolset routes deny access, but the workflow save and runtime path did not apply the same authoriz
nvd
CVE-2026-40100P3MEDIUMCVSS 5.3fixed in 4.14.10.32026-04-10
CVE-2026-40100 [MEDIUM] CWE-918 CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The internal IP check in isInternalAddress() only blocks private IPs when CHECK_INTERNAL_IP=true, which is not the default. This allows unauthenticated attackers to perform SSRF against internal net
nvd
CVE-2026-42344P3MEDIUMCVSS 6.3≤ 4.14.112026-05-08
CVE-2026-42344 [MEDIUM] CWE-367 CVE-2026-42344: FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding (TOCTOU — Time-of-Check to Time-of-Use). The function resolves the hostname via dns.resolve4()/dns.resolve6() and checks resolved IPs against private ranges, but the
nvd
CVE-2025-27600P3MEDIUMCVSS 6.5fixed in 4.9.02025-03-06
CVE-2025-27600 [MEDIUM] CWE-918 CVE-2025-27600: FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not per FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can initiate an intranet IP request, causing the system to initiate a request through the intranet and potentially obtain some private data on the intranet. This issue is fixed in 4.9.0.
nvd
CVE-2026-26003P4MEDIUMCVSS 5.4v>= 4.14.0, < 4.14.5-fix2026-02-10
CVE-2026-26003 [MEDIUM] CWE-601 CVE-2026-26003: FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the p FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx without authentication, thereby threatening the plugin system. This may cause the plugin system to crash and the loss of plugin installation status, but it will not result in key leakage. For older versions,
nvd
CVE-2026-26075P4MEDIUMCVSS 5.4fixed in 4.14.72026-02-12
CVE-2026-26075 [MEDIUM] CWE-352 CVE-2026-26075: FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization has added stricter internal networ
nvd
CVE-2025-62612P4MEDIUMCVSS 5.3fixed in 4.11.12025-10-22
CVE-2025-62612 [MEDIUM] CWE-918 CVE-2025-62612: FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.
nvd
CVE-2025-52552P4MEDIUMCVSS 6.1fixed in 4.9.122025-06-21
CVE-2025-52552 [MEDIUM] CWE-79 CVE-2025-52552: FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9
nvd
CVE-2026-44286P4LOWCVSS 2.3fixed in 4.14.172026-05-08
CVE-2026-44286 [LOW] CWE-918 CVE-2026-44286: FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side R FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows attackers (or authenticated users with App editing privileges) to send arbitrary HTTP requests to internal/private network addresses. The fetchData function in the lafModule workflow node uses axios to fetch use
nvd
Labring Fastgpt vulnerabilities | cvebase