PT-2026-39205 · Fastgpt · Fastgpt

Jinyimeng01

·

Published

2026-05-08

·

Updated

2026-06-17

·

CVE-2026-42302

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastGPT versions 4.14.10 through 4.14.12
Description The agent-sandbox component allows unauthenticated Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine. The startup script entrypoint.sh initializes code-server with the --auth none flag and binds the service to all network interfaces at '0.0.0.0:8080'. This configuration enables any user with network access to the port to bypass authentication and gain full control over the sandbox environment.
Recommendations Update to version 4.14.13.

Exploit

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42302

Affected Products

Fastgpt