labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.15.0之前版本存在授权问题漏洞,该漏洞源于对/api/core/ai/record/getRecord接口的权限验证不足,仅通过requestId加载LLM请求和响应记录而未进行团队范围检查,导致任何经过身份验证的用户在知晓requestId的情况下可读取其他团队的提示词、检索的RAG块和完成结果。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55418 | 8.6 HIGH | FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-t |
| CVE-2026-54607 | 7.7 HIGH | FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the is |
| CVE-2026-54601 | 6.3 MEDIUM | FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant |
No comments yet