PT-2026-39210 · Fastgpt · Fastgpt

Lowc121914

+1

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-44286

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FastGPT versions prior to 4.14.17
Description An unauthenticated Server-Side Request Forgery (SSRF) allows attackers or authenticated users with App editing privileges to send arbitrary HTTP requests to internal or private network addresses. The fetchData() function in the lafModule workflow node uses axios to fetch user-controlled URLs without validating them against the isInternalAddress internal network blocklist guard, which bypasses SSRF protections. SSRF is a flaw where an attacker can force a server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
Recommendations Update to version 4.14.17.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-44286

Affected Products

Fastgpt