PT-2026-33519 · Fastgpt · Fastgpt
August829
·
Published
2026-04-17
·
Updated
2026-04-27
·
CVE-2026-40351
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FastGPT versions prior to 4.14.9.5
Description
The password-based login endpoint uses TypeScript type assertion without runtime validation. This allows an unauthenticated attacker to use a MongoDB query operator object, such as
{"$ne": ""}, in the password field. This NoSQL injection—a technique where an attacker uses database-specific syntax to manipulate queries—bypasses authentication checks, enabling unauthorized access to any user account, including the root administrator.Recommendations
Update to version 4.14.9.5.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastgpt