FastGPT versions prior to 4.14.10.4 contain a Broken Access Control vulnerability (IDOR/BOLA) that allows authenticated users to access and execute applications belonging to other teams by manipulating the application ID parameter. The vulnerability exists because while the API validates team authentication tokens, it fails to verify that the requested application belongs to the authenticated user's team, enabling cross-tenant data exposure and unauthorized workflow execution. The vulnerability carries a HIGH severity rating (CVSS 8.1) with a network-based attack vector requiring only low complexity and valid authentication credentials. The impact is significant, with HIGH confidentiality and integrity compromises possible, though system availability is not affected. An authenticated attacker requires minimal effort to exploit this vulnerability, making it a substantial risk to multi-tenant deployments. The vulnerability is currently marked as active on vulnerability tracking lists and shows elevated community attention despite a relatively low EPSS score. There are no known public exploits documented, and the vulnerability has not yet been formally added to known exploited vulnerabilities (KEV) catalogs. Organizations running FastGPT should prioritize upgrading to version 4.14.10.4 or later to remediate this access control flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.14.10.4CPE matchmatch criteria | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.