漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')
Vulnerability Description
FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official deployment templates. An unauthenticated attacker can self-sign an HS256 JWT and reach /api/invoke/userInfo to disclose cross-tenant user PII by attacker-supplied tmbId values, or /api/invoke/fileUpload to write attacker-controlled content into chat files. This issue is fixed in version 4.15.0-beta5.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
labring FastGPT 信任管理问题漏洞
Vulnerability Description
labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.15.0-beta4版本存在信任管理问题漏洞,该漏洞源于使用硬编码的INVOKE_TOKEN_SECRET常量字符串进行JWT签名验证,导致未经身份验证的攻击者可自签HS256令牌,访问/api/invoke/userInfo暴露跨租户用户PII信息或通过/api/invoke/fileUpload向聊天文件中写入任意内容。
CVSS Information
N/A
Vulnerability Type
N/A