Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40351

32
FAUCET Score

CVE-2026-40351 is a critical NoSQL injection vulnerability in FastGPT, an AI Agent building platform, affecting all versions prior to 4.14.9.5. The flaw exists in the password-based login endpoint, which fails to perform runtime validation on user-supplied credentials, instead relying solely on TypeScript type assertions. An unauthenticated attacker can exploit this by injecting MongoDB query operators such as {"$ne": ""} in the password field to bypass authentication and gain unauthorized access to any user account, including the root administrator account. The vulnerability presents a critical severity profile with a CVSS score of 9.8, reflecting its network-accessible nature, lack of authentication requirements, and complete compromise potential across confidentiality, integrity, and availability. The attack requires no user interaction and can be executed remotely with minimal complexity, making it trivially exploitable by any attacker with network access to affected instances. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.000610000 indicating relatively low prevalence among disclosed CVEs. The vulnerability has not been designated for inclusion in the KEV catalog, and community attention appears limited based on its inactive status on security monitoring hotlists. Organizations running FastGPT versions prior to 4.14.9.5 should prioritize immediate patching to mitigate this critical authentication bypass risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.9.5CPE matchmatch criteria
cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 27th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d
Patch
github.com / labring/FastGPT/releases/tag/v4.14.9.5
ProductRelease Notes
github.com / labring/FastGPT/security/advisories/GHSA-x8mx-2mr7-h9xg
ExploitMitigationVendor Advisory