โ† All reports

The FastGPT AI platform has critical security vulnerabilities that allow attackers to bypass authentication and inject malicious queries into the database.

CybersecurityApr 17, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two critical vulnerabilities in the FastGPT AI platform by Labring, both related to security flaws that allow attackers to bypass authentication and inject malicious queries into the database. These vulnerabilities highlight significant security risks in AI development platforms.

Claims

The FastGPT AI platform has critical security vulnerabilities that allow attackers to bypass authentication and inject malicious queries into the database.
Parent: AIEntity: FastGPTImpact: negativeDate: Apr 17, 2026Target: The security of the FastGPT AI platform

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23557 ๐Ÿ“Š Score: 9.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: FastGPT ๐Ÿข Vendor: labring ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23557 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23559 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: FastGPT ๐Ÿข Vendor: labring ๐Ÿ“… Updated: 2026-04-17 ๐Ÿ“ FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23559 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability