PT-2026-7419 · Fastgpt · Fastgpt
Jingfelix
·
Published
2026-02-10
·
Updated
2026-02-10
·
CVE-2026-26003
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
FastGPT versions 4.14.0 through 4.14.5
Description
FastGPT, an AI Agent building platform, has an issue where the plugin system can be accessed directly through the API endpoint
/api/plugin/xxx without authentication. This affects versions 4.14.0 to 4.14.5 and could lead to the plugin system crashing and the loss of plugin installation status. Older versions are considered to have a negligible impact as they only offer information-gathering interfaces. The issue does not result in key leakage.Recommendations
Versions prior to 4.14.5-fix are affected.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastgpt