CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Labring Remove filter Clear all
CVE-2026-84301 MEDIUM

FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests

CVSS 6.3 EPSS 0.29% Sep 22, 2026
CVE-2026-68929 CRITICAL

FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization

CVSS 9.3 EPSS 0.43% Aug 27, 2026
CVE-2026-61643 MEDIUM

FastGPT: workflow runtime can execute another user's private HTTP toolset

CVSS 5.9 EPSS 0.25% Jul 15, 2026
CVE-2026-50562 CRITICAL

FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows

CVSS 9.3 EPSS 0.21% Jul 15, 2026
CVE-2026-61646 MEDIUM

FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects

CVSS 6.3 EPSS 0.36% Jul 15, 2026
CVE-2026-61644 HIGH

FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup

CVSS 7.7 EPSS 0.41% Jul 15, 2026
CVE-2026-61684 HIGH

FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')

CVSS 8.8 EPSS 0.51% Jul 15, 2026
CVE-2026-54602 HIGH

FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord

CVSS 7.1 EPSS 0.36% Jul 7, 2026
CVE-2026-54607 HIGH

FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)

CVSS 7.7 EPSS 0.52% Jul 7, 2026
CVE-2026-55418 HIGH

FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)

CVSS 8.6 EPSS 0.48% Jul 7, 2026
CVE-2026-54601 MEDIUM

FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion

CVSS 6.3 EPSS 0.40% Jul 7, 2026
CVE-2026-44287 MEDIUM

FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable

CVSS 6.3 EPSS 0.43% May 29, 2026
CVE-2026-44285 HIGH

FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API

CVSS 7.7 EPSS 0.36% May 29, 2026
CVE-2026-44286 LOW

FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation

CVSS 2.3 EPSS 0.39% May 8, 2026
CVE-2026-44284 MEDIUM

FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution

CVSS 6.3 EPSS 0.40% May 8, 2026
CVE-2026-42345 HIGH

FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot

CVSS 7.7 EPSS 0.36% May 8, 2026
CVE-2026-42344 MEDIUM

FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints

CVSS 6.3 EPSS 0.23% May 8, 2026
CVE-2026-42343 MEDIUM

FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion

CVSS 6.3 EPSS 0.45% May 8, 2026
CVE-2026-42302 CRITICAL

FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox

CVSS 9.8 EPSS 1.29% May 8, 2026
CVE-2026-40352 HIGH

FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover

CVSS 8.8 EPSS 0.53% Apr 17, 2026
CVE-2026-40351 CRITICAL

FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass

CVSS 9.8 EPSS 0.60% Apr 17, 2026
CVE-2026-40252 MEDIUM

Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT

CVSS 5.3 EPSS 0.44% Apr 10, 2026
CVE-2026-40100 MEDIUM

FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default

CVSS 5.3 EPSS 0.40% Apr 10, 2026
CVE-2026-34162 CRITICAL

FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft

CVSS 10.0 EPSS 0.62% Mar 31, 2026
CVE-2026-34163 HIGH

Server-Side Request Forgery via MCP Tools Endpoint in FastGPT

CVSS 7.7 EPSS 0.42% Mar 31, 2026

Showing 1 to 25 CVEs · page 1 (more available)