Fastgpt

Fastgpt

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 10.04.2026 16:39:25
  • Zuletzt bearbeitet 15.04.2026 19:02:57

FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The internal IP check in isInternalAddress() only blocks private IPs when CHECK_INTERNAL_IP=true,...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 31.03.2026 13:43:20
  • Zuletzt bearbeitet 01.04.2026 18:38:39

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 31.03.2026 13:43:11
  • Zuletzt bearbeitet 01.04.2026 18:28:47

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept a user-supplied URL parameter and make server-side...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 20.03.2026 08:37:16
  • Zuletzt bearbeitet 23.03.2026 15:42:34

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs wi...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 11.03.2026 21:30:26
  • Zuletzt bearbeitet 19.03.2026 17:38:40

FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes guardrails intended to prevent file writes (static detection + seccomp). These guardrails are bypassable by remapping stdout (fd 1) t...

  • EPSS 0.02%
  • Veröffentlicht 12.02.2026 21:42:58
  • Zuletzt bearbeitet 23.02.2026 16:52:24

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal ...

  • EPSS 0.09%
  • Veröffentlicht 10.02.2026 18:16:39
  • Zuletzt bearbeitet 23.02.2026 18:06:14

FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx without authentication, thereby threatening the plugin system. This may cause the plugin system to crash a...

  • EPSS 0.04%
  • Veröffentlicht 22.10.2025 20:45:17
  • Zuletzt bearbeitet 29.12.2025 19:08:53

FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 21.06.2025 02:15:07
  • Zuletzt bearbeitet 29.12.2025 19:06:40

FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicio...

  • EPSS 0.83%
  • Veröffentlicht 09.06.2025 12:42:46
  • Zuletzt bearbeitet 29.12.2025 19:09:21

FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sandbox) is a specialized, isolated environment used by FastGPT to safely ...