CVE-2026-34163 is a Server-Side Request Forgery (SSRF) vulnerability affecting FastGPT versions prior to 4.14.9.5. An authenticated attacker can exploit the MCP tools endpoints by supplying a malicious URL, enabling server-side HTTP requests to internal network addresses. Rated 7.7 High (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), this flaw allows for scanning internal networks, accessing cloud metadata services, and interacting with internal services, leading to a high confidentiality impact. There is currently no evidence of active exploitation, nor are public exploit codes available, and community discussion remains low. Organizations using FastGPT should update to version 4.14.9.5 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.14.9.5CPE matchmatch criteria | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.