PT-2026-29262 · Fastgpt · Fastgpt
August829
·
Published
2026-03-31
·
Updated
2026-04-01
·
CVE-2026-34162
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FastGPT versions prior to 4.14.9.5
Description
FastGPT is an AI Agent building platform. The HTTP tools testing endpoint ('/api/core/app/httpTools/runTool') was exposed without authentication in versions prior to 4.14.9.5. This endpoint functions as a full HTTP proxy, accepting a user-supplied
baseUrl, toolPath, HTTP method, custom headers, and body, then making a server-side HTTP request and returning the complete response. This allows an unauthenticated attacker to potentially exfiltrate API tokens, access internal services, and send arbitrary HTTP requests. This issue enables a Server-Side Request Forgery (SSRF) condition, potentially leading to Remote Code Execution (RCE).Recommendations
Update FastGPT to version 4.14.9.5 or later.
Exploit
Fix
SSRF
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fastgpt