All 33 CVE vulnerabilities found in FastGPT, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities affecting FastGPT, an open-source platform for building large language model applications. It collects recorded security weaknesses, including common software flaws such as cross-site scripting, injection attacks, and improper access control issues, covering the period from the project's initial releases through the most recent updates. Visitors can track the vendor's published security advisories, analyze the prevalence of specific weakness classes within the codebase, and review the complete vulnerability history to identify recurring patterns or unpatched issues in deployed instances. The data is presented as a structured inventory, enabling security teams to assess risk exposure and prioritize remediation efforts based on severity and exploitability.
Vendor: labring
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-52552 | FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSS CWE-601 | 6.1AI | Medium AI | 2025-06-21 |
| CVE-2025-49131 | FastGPT Sandbox Vulnerable to Sandbox Bypass CWE-732 | 6.3 | Medium | 2025-06-09 |
| CVE-2025-27600 | FastGPT SSRF CWE-918 | 7.5 | - | 2025-03-06 |
All 33 known CVE vulnerabilities affecting FastGPT with full Chinese analysis, references, and POCs where available.