PT-2025-26492 · Fastgpt · Fastgpt

C121914Yu

·

Published

2025-06-21

·

Updated

2025-12-29

·

CVE-2025-52552

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: FastGPT versions prior to 4.9.12
Description: The issue concerns the LastRoute Parameter on the login page, which is vulnerable to open redirect and DOM-based XSS due to improper validation and lack of sanitization. This allows attackers to execute malicious JavaScript or redirect users to attacker-controlled sites.
Recommendations: For versions prior to 4.9.12, update to version 4.9.12 to resolve the issue. As a temporary workaround, consider restricting access to the LastRoute Parameter on the login page to minimize the risk of exploitation. Avoid using the LastRoute parameter in the affected login page until the issue is resolved.

Exploit

Fix

Open Redirect

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-52552
GHSA-R976-RFRV-Q24M

Affected Products

Fastgpt