labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT存在安全漏洞,该漏洞源于工作流配置问题,导致可利用高权限工作流任务下载来自不受信任的拉取请求构建的制品,从而允许攻击者控制的Docker镜像被推送至GHCR,并在文档预览中部署,可能导致权限许可和访问控制问题及软件供应链风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61644 | 7.7 HIGH | FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text d |
| CVE-2026-61643 | 5.9 MEDIUM | FastGPT: workflow runtime can execute another user's private HTTP toolset |
| CVE-2026-61684 | FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default | |
| CVE-2026-61646 | FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects |
No comments yet