labring FastGPT是labring公司开源的一款基于大语言模型的开源知识库问答系统。 labring FastGPT 4.15.0-beta4版本存在信任管理问题漏洞,该漏洞源于使用硬编码的INVOKE_TOKEN_SECRET常量字符串进行JWT签名验证,导致未经身份验证的攻击者可自签HS256令牌,访问/api/invoke/userInfo暴露跨租户用户PII信息或通过/api/invoke/fileUpload向聊天文件中写入任意内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61644 | 7.7 HIGH | FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text d |
| CVE-2026-61643 | 5.9 MEDIUM | FastGPT: workflow runtime can execute another user's private HTTP toolset |
| CVE-2026-61646 | FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects | |
| CVE-2026-50562 | FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows |
No comments yet