labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.15.0-beta5之前版本存在授权问题漏洞,该漏洞源于文件处理程序授权无关资源,并使用直接从请求中获取的密钥签名或读取S3对象,而未检查该密钥是否属于调用者的团队,导致攻击者可通过chat-file presign端点或dataset preview端点提供其他团队的密钥并获取其文件内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54607 | 7.7 HIGH | FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the is |
| CVE-2026-54601 | 6.3 MEDIUM | FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant |
| CVE-2026-54602 | FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getReco |
No comments yet