Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-68929— FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization

Quick assessment

Affected
labring FastGPT
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: FastGPT 是一个用于在知识库上构建 AI 应用的开源 LLM 平台。在 4.15.2 之前的版本中,微信(iLink)分享渠道的端点仅使用公开的 shareId 来授权请求,缺乏对认证身份或团队所有权的校验。因此,未认证的知道受害者团队 shareId 的攻击者可以让该团队的微信机器人下线,或者将渠道劫持到攻击者自己的机器人上:登出端点仅受“存在性检查”保护,却会清除 outLink 中存储的微信令牌;二维码状态端点则完全没有进行任何授权检查,并且会将攻击者提供的机器人凭据写入由

CVSS 9.3 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-68929

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization
Source: CVE Program / CVE List V5
Vulnerability Description
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result, an unauthenticated attacker who knows a victim team's shareId can take that team's WeChat bot offline or hijack the channel to their own bot: the logout endpoint is gated only by an existence check yet wipes the outLink's stored WeChat token, and the QR-code status endpoint performs no authorization at all and writes attacker-supplied bot credentials into the outLink identified by shareId. By generating a QR for a victim shareId, scanning it with their own WeChat, and calling the status endpoint, an attacker binds the victim team's app to the attacker's bot, exposing the app's private responses, displacing the legitimate binding, and consuming the victim's resources. The shareId is exposed in every shared chat URL, iframe, and embed, so it is not a secret. This issue is fixed in version 4.15.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
labring FastGPT >= 4.14.10, < 4.14.29 -

II. Public POCs for CVE-2026-68929

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-68929

登录查看更多情报信息。

Vendor Advisories for CVE-2026-68929 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-68929

No comments yet


Leave a comment