FastGPT
Labring · 33 CVEs
FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests
Sep 22, 2026
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
Aug 27, 2026
FastGPT: workflow runtime can execute another user's private HTTP toolset
Jul 15, 2026
FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
Jul 15, 2026
FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects
Jul 15, 2026
FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lo…
Jul 15, 2026
FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')
Jul 15, 2026
FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord
Jul 7, 2026
FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)
Jul 7, 2026
FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)
Jul 7, 2026
FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion
Jul 7, 2026
FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable
May 29, 2026
FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API
May 29, 2026
FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation
May 8, 2026
FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution
May 8, 2026
FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding,…
May 8, 2026
FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints
May 8, 2026
FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion
May 8, 2026
FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox
May 8, 2026
FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover
Apr 17, 2026
FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass
Apr 17, 2026
Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT
Apr 10, 2026
FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default
Apr 10, 2026
FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft
Mar 31, 2026
Server-Side Request Forgery via MCP Tools Endpoint in FastGPT
Mar 31, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-84301 | FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests | MEDIUM | 0.29% | Sep 22, 2026 |
| CVE-2026-68929 | FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization | CRITICAL | 0.43% | Aug 27, 2026 |
| CVE-2026-61643 | FastGPT: workflow runtime can execute another user's private HTTP toolset | MEDIUM | 0.25% | Jul 15, 2026 |
| CVE-2026-50562 | FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows | CRITICAL | 0.21% | Jul 15, 2026 |
| CVE-2026-61646 | FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects | MEDIUM | 0.36% | Jul 15, 2026 |
| CVE-2026-61644 | FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup | HIGH | 0.41% | Jul 15, 2026 |
| CVE-2026-61684 | FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token') | HIGH | 0.51% | Jul 15, 2026 |
| CVE-2026-54602 | FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord | HIGH | 0.36% | Jul 7, 2026 |
| CVE-2026-54607 | FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard) | HIGH | 0.52% | Jul 7, 2026 |
| CVE-2026-55418 | FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure) | HIGH | 0.48% | Jul 7, 2026 |
| CVE-2026-54601 | FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion | MEDIUM | 0.40% | Jul 7, 2026 |
| CVE-2026-44287 | FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable | MEDIUM | 0.43% | May 29, 2026 |
| CVE-2026-44285 | FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API | HIGH | 0.36% | May 29, 2026 |
| CVE-2026-44286 | FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation | LOW | 0.39% | May 8, 2026 |
| CVE-2026-44284 | FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution | MEDIUM | 0.40% | May 8, 2026 |
| CVE-2026-42345 | FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot | HIGH | 0.36% | May 8, 2026 |
| CVE-2026-42344 | FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints | MEDIUM | 0.23% | May 8, 2026 |
| CVE-2026-42343 | FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion | MEDIUM | 0.45% | May 8, 2026 |
| CVE-2026-42302 | FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox | CRITICAL | 1.29% | May 8, 2026 |
| CVE-2026-40352 | FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover | HIGH | 0.53% | Apr 17, 2026 |
| CVE-2026-40351 | FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass | CRITICAL | 0.60% | Apr 17, 2026 |
| CVE-2026-40252 | Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT | MEDIUM | 0.44% | Apr 10, 2026 |
| CVE-2026-40100 | FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default | MEDIUM | 0.40% | Apr 10, 2026 |
| CVE-2026-34162 | FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft | CRITICAL | 0.62% | Mar 31, 2026 |
| CVE-2026-34163 | Server-Side Request Forgery via MCP Tools Endpoint in FastGPT | HIGH | 0.42% | Mar 31, 2026 |
Showing 1 to 25 of 33 CVEs