PT-2026-29262 · Fastgpt · Fastgpt

·

CVE-2026-34162

·

Published

2026-03-31

·

Updated

2026-04-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions FastGPT versions prior to 4.14.9.5
Description FastGPT is an AI Agent building platform. The HTTP tools testing endpoint ('/api/core/app/httpTools/runTool') was exposed without authentication in versions prior to 4.14.9.5. This endpoint functions as a full HTTP proxy, accepting a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then making a server-side HTTP request and returning the complete response. This allows an unauthenticated attacker to potentially exfiltrate API tokens, access internal services, and send arbitrary HTTP requests. This issue enables a Server-Side Request Forgery (SSRF) condition, potentially leading to Remote Code Execution (RCE).
Recommendations Update FastGPT to version 4.14.9.5 or later.

Exploit

Fix

SSRF

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34162
GHSA-W36R-F268-PWRJ

Affected Products

Fastgpt