PT-2026-33520 · Fastgpt · Fastgpt

·

CVE-2026-40352

·

Published

2026-04-17

·

Updated

2026-04-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastGPT versions prior to 4.14.9.5
Description The password change endpoint is susceptible to NoSQL injection, a technique where MongoDB query operators are injected into a database query. An authenticated attacker can use this to bypass the verification of the old password. This allows a user with a low-privileged session to change account passwords without knowing the current one, potentially leading to full account takeover and persistence.
Recommendations Update to version 4.14.9.5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40352
GHSA-422W-VRFJ-72G6

Affected Products

Fastgpt