PT-2025-43407 · Fastgpt · Fastgpt

0Gur1

·

Published

2025-10-22

·

Updated

2025-12-29

·

CVE-2025-62612

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FastGPT versions prior to 4.11.1
Description FastGPT is a platform for building AI Agents. Versions of FastGPT before 4.11.1 contain a Server-Side Request Forgery (SSRF) issue in the workflow file reading node. The system does not verify the security of network links, which could allow for SSRF attacks.
Recommendations Update to version 4.11.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-62612
GHSA-573G-3567-8PHG

Affected Products

Fastgpt