Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61644— FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup

CVSS 7.7 · High EPSS 0.24% · P16

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProductVersion RangeStatus
labringFastGPT>= 4.14.17, < 4.15.0-beta5affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-61644

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup
Source: CVE Program / CVE List V5
Vulnerability Description
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId center-node lookup is not bound to that authorized context. A low-privileged tenant user can call the endpoint with valid attacker-owned appId, chatId, chatItemDataId, and collectionId values while supplying another tenant's dataset data id as initialId, causing the response to include foreign dataset quote or full-text content. This issue is fixed in version 4.15.0-beta5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5
Vulnerability Title
labring FastGPT 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.14.17版本至4.15.0-beta5之前版本存在授权问题漏洞,该漏洞源于对POST /api/core/chat/record/getCollectionQuote端点的授权验证不当,initialId中心节点查找未绑定已授权上下文,可能导致低权限租户用户利用有效参数获取其他租户的数据集引用或全文内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
labringFastGPT >= 4.14.17, < 4.15.0-beta5 -

II. Public POCs for CVE-2026-61644

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 6949 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-61644

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61644 (2)

Vendor Advisories for CVE-2026-61644 (1)

Vendor Pages for CVE-2026-61644 (1)

Same Patch Batch · labring · 2026-07-15 · 5 CVEs total

CVE-2026-616435.9 MEDIUMFastGPT: workflow runtime can execute another user's private HTTP toolset
CVE-2026-61684FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default
CVE-2026-61646FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects
CVE-2026-50562FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows

IV. Related Vulnerabilities

V. Comments for CVE-2026-61644

No comments yet


Leave a comment