Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

labring — Vulnerabilities & Security Advisories 37

Browse all 37 CVE security advisories affecting labring. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Labring operates as a cloud service provider focusing on AI and big data infrastructure solutions. Historically, their products have been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for the majority of their 18 recorded CVEs. Notable security characteristics include exposure in container orchestration platforms and API endpoints, with several critical RCE vulnerabilities identified in their Kubernetes management tools. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in core infrastructure components suggests potential risks for enterprise deployments relying on their platform.

Top products by labring: FastGPT sealos laf
CVE ID Title CVSS Severity Published
CVE-2026-84301 FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests — FastGPT CWE-918 6.3 Medium 2026-09-22
CVE-2026-68929 FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorization — FastGPT CWE-862 9.3 Critical 2026-08-27
CVE-2026-61643 FastGPT: workflow runtime can execute another user's private HTTP toolset — FastGPT CWE-863 5.9 Medium 2026-07-15
CVE-2026-50562 FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows — FastGPT CWE-266 - - 2026-07-15
CVE-2026-61646 FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects — FastGPT CWE-918 - - 2026-07-15
CVE-2026-61644 FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup — FastGPT CWE-863 7.7 High 2026-07-15
CVE-2026-61684 FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token') — FastGPT CWE-798 - - 2026-07-15
CVE-2026-54602 FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord — FastGPT CWE-639 - - 2026-07-07
CVE-2026-54607 FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard) — FastGPT CWE-918 7.7 High 2026-07-07
CVE-2026-55418 FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure) — FastGPT CWE-639 8.6 High 2026-07-07
CVE-2026-54601 FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion — FastGPT CWE-915 6.3 Medium 2026-07-07
CVE-2026-44287 FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable — FastGPT CWE-94 6.3 Medium 2026-05-29
CVE-2026-44285 FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API — FastGPT CWE-918 7.7 High 2026-05-29
CVE-2026-44286 FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation — FastGPT CWE-918 8.1AI High AI 2026-05-08
CVE-2026-44284 FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution — FastGPT CWE-918 6.3 Medium 2026-05-08
CVE-2026-42345 FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot — FastGPT CWE-918 7.7 High 2026-05-08
CVE-2026-42344 FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints — FastGPT CWE-367 6.3 Medium 2026-05-08
CVE-2026-42343 FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion — FastGPT CWE-400 7.5AI High AI 2026-05-08
CVE-2026-42302 FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox — FastGPT CWE-306 9.8 Critical 2026-05-08
CVE-2026-40352 FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover — FastGPT CWE-943 8.8 High 2026-04-17
CVE-2026-40351 FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass — FastGPT CWE-943 9.8 Critical 2026-04-17
CVE-2026-40252 Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT — FastGPT CWE-284 8.8 - 2026-04-10
CVE-2026-40100 FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default — FastGPT CWE-918 5.3 Medium 2026-04-10
CVE-2026-34162 FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft — FastGPT CWE-306 10.0 Critical 2026-03-31
CVE-2026-34163 Server-Side Request Forgery via MCP Tools Endpoint in FastGPT — FastGPT CWE-918 7.7 High 2026-03-31
CVE-2026-33075 FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml — FastGPT CWE-494 7.5 - 2026-03-20
CVE-2026-32128 FastGPT Python Sandbox Bypass of File-Write Restriction — FastGPT CWE-184 6.3 Medium 2026-03-11
CVE-2026-26075 Cross-Site Request Forgery (CSRF) in FastGPT — FastGPT CWE-352 5.3AI Medium AI 2026-02-12
CVE-2026-26003 FastGPT Plugin forwarding request is not authenticated, posing a serious risk of attack — FastGPT CWE-601 6.5AI Medium AI 2026-02-10
CVE-2025-62612 FastGPT File Reading Node SSRF Vulnerability — FastGPT CWE-918 9.1AI Critical AI 2025-10-22

This page lists every published CVE security advisory associated with labring. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.