This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: FastGPT < 4.14.9.5 has a critical auth bypass. ๐ฅ **Consequences**: Attackers can inject MongoDB operators via the password login endpoint.โฆ
๐ก๏ธ **Root Cause**: CWE-943 (Improper Neutralization of Special Elements in Data). ๐ **Flaw**: The login endpoint uses TypeScript type assertions without runtime checks.โฆ
๐ **Public Exp?**: No specific PoC code provided in data. ๐ **Status**: Advisory confirmed via GitHub Security Advisories (GHSA-x8mx-2mr7-h9xg). โ ๏ธ **Risk**: High likelihood of wild exploitation due to low complexity.
Q7How to self-check? (Features/Scanning)
๐ **Check**: Scan for FastGPT instances. ๐ **Verify**: Check version number in UI or API response. ๐ ๏ธ **Tool**: Look for the specific login endpoint behavior if fuzzing. ๐ฉ **Flag**: Any version < 4.14.9.5 is vulnerable.
Q8Is it fixed officially? (Patch/Mitigation)
โ **Fixed**: Yes. ๐ฅ **Patch**: Upgrade to **FastGPT v4.14.9.5** or later. ๐ **Source**: Official GitHub Release & Commit bd966d479fbe414d02679cf79f9eaaab3d100a2d.
Q9What if no patch? (Workaround)
๐ง **No Patch?**: Implement strict input validation on the login endpoint. ๐ **Mitigate**: Block direct MongoDB query operator injection patterns. ๐ **Limit**: Restrict network access to the login API if possible.โฆ
๐ฅ **Urgency**: CRITICAL. ๐ **CVSS**: 9.8 (High). ๐จ **Action**: Patch IMMEDIATELY. This is an unauthenticated remote code execution equivalent. Do not delay.