The FastGPT AI platform has critical security vulnerabilities that allow attackers to bypass authentication and inject malicious queries into the database.
Claims
The FastGPT AI platform has critical security vulnerabilities that allow attackers to bypass authentication and inject malicious queries into the database.
Parent: AIEntity: FastGPTImpact: negativeDate: Apr 17, 2026Target: The security of the FastGPT AI platform
Source posts
๐จ EUVD-2026-23557
๐ Score: 9.8/10 (CVSS v3.1)
๐ฆ Product: FastGPT
๐ข Vendor: labring
๐
Updated: 2026-04-17
๐ FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23557
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-23559
๐ Score: 8.8/10 (CVSS v3.1)
๐ฆ Product: FastGPT
๐ข Vendor: labring
๐
Updated: 2026-04-17
๐ FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23559
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 17, 2026
#cybersecurity#infosec#euvd#cve#vulnerability