labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.15.0-beta4之前版本存在服务端请求伪造漏洞,该漏洞源于HTTP-tool OpenAPI schema导入器在将URL传递给SwaggerParser.bundle之前仅验证顶层URL,其远程引用解析器在获取$ref URL时没有FastGPT内部地址保护并将获取的内容内联返回,可能导致经过身份验证的团队成员读取内部服务或云元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55418 | 8.6 HIGH | FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-t |
| CVE-2026-54601 | 6.3 MEDIUM | FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant |
| CVE-2026-54602 | FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getReco |
No comments yet