FastGPT

Labring · 33 CVEs

CVE-2026-84301
MEDIUM

FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests

Sep 22, 2026

CVE-2026-68929
CRITICAL

FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization

Aug 27, 2026

CVE-2026-61643
MEDIUM

FastGPT: workflow runtime can execute another user's private HTTP toolset

Jul 15, 2026

CVE-2026-50562
CRITICAL

FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows

Jul 15, 2026

CVE-2026-61646
MEDIUM

FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects

Jul 15, 2026

CVE-2026-61644
HIGH

FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lo…

Jul 15, 2026

CVE-2026-61684
HIGH

FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')

Jul 15, 2026

CVE-2026-54602
HIGH

FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord

Jul 7, 2026

CVE-2026-54607
HIGH

FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)

Jul 7, 2026

CVE-2026-55418
HIGH

FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)

Jul 7, 2026

CVE-2026-54601
MEDIUM

FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion

Jul 7, 2026

CVE-2026-44287
MEDIUM

FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable

May 29, 2026

CVE-2026-44285
HIGH

FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API

May 29, 2026

CVE-2026-44286
LOW

FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation

May 8, 2026

CVE-2026-44284
MEDIUM

FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution

May 8, 2026

CVE-2026-42345
HIGH

FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding,…

May 8, 2026

CVE-2026-42344
MEDIUM

FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints

May 8, 2026

CVE-2026-42343
MEDIUM

FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion

May 8, 2026

CVE-2026-42302
CRITICAL

FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox

May 8, 2026

CVE-2026-40352
HIGH

FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover

Apr 17, 2026

CVE-2026-40351
CRITICAL

FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass

Apr 17, 2026

CVE-2026-40252
MEDIUM

Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT

Apr 10, 2026

CVE-2026-40100
MEDIUM

FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default

Apr 10, 2026

CVE-2026-34162
CRITICAL

FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft

Mar 31, 2026

CVE-2026-34163
HIGH

Server-Side Request Forgery via MCP Tools Endpoint in FastGPT

Mar 31, 2026

Showing 1 to 25 of 33 CVEs