CVE-2026-40351 is a critical NoSQL injection vulnerability in FastGPT, an AI Agent building platform, affecting all versions prior to 4.14.9.5. The flaw exists in the password-based login endpoint, which fails to perform runtime validation on user-supplied credentials, instead relying solely on TypeScript type assertions. An unauthenticated attacker can exploit this by injecting MongoDB query operators such as {"$ne": ""} in the password field to bypass authentication and gain unauthorized access to any user account, including the root administrator account. The vulnerability presents a critical severity profile with a CVSS score of 9.8, reflecting its network-accessible nature, lack of authentication requirements, and complete compromise potential across confidentiality, integrity, and availability. The attack requires no user interaction and can be executed remotely with minimal complexity, making it trivially exploitable by any attacker with network access to affected instances. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.000610000 indicating relatively low prevalence among disclosed CVEs. The vulnerability has not been designated for inclusion in the KEV catalog, and community attention appears limited based on its inactive status on security monitoring hotlists. Organizations running FastGPT versions prior to 4.14.9.5 should prioritize immediate patching to mitigate this critical authentication bypass risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.14.9.5CPE matchmatch criteria | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.