CVE-2026-40352 is a NoSQL injection vulnerability in FastGPT, an AI Agent building platform, affecting all versions prior to 4.14.9.5. The flaw exists in the password change endpoint, allowing authenticated attackers to bypass old password verification by injecting MongoDB query operators, potentially enabling account takeover and persistence mechanisms. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low-level privileges and user interaction. The attack has low complexity and results in high impact across confidentiality, integrity, and availability. Notably, an attacker can change account passwords without knowing the current credentials, and combined with ID manipulation could affect other users. Exploitation status remains limited, with the vulnerability showing no evidence of active exploitation in the wild (KEV designation inactive) and minimal community attention relative to other CVEs (EPSS percentile rank of 0.0003). The vulnerability has been patched in version 4.14.9.5, and organizations running FastGPT should prioritize immediate updates to remediate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.14.9.5CPE matchmatch criteria | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.