PT-2026-33519 · Fastgpt · Fastgpt

·

CVE-2026-40351

·

Published

2026-04-17

·

Updated

2026-04-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastGPT versions prior to 4.14.9.5
Description The password-based login endpoint uses TypeScript type assertion without runtime validation. This allows an unauthenticated attacker to use a MongoDB query operator object, such as {"$ne": ""}, in the password field. This NoSQL injection—a technique where an attacker uses database-specific syntax to manipulate queries—bypasses authentication checks, enabling unauthorized access to any user account, including the root administrator.
Recommendations Update to version 4.14.9.5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40351
GHSA-X8MX-2MR7-H9XG

Affected Products

Fastgpt