FastGPT is a focused artificial-intelligence application platform whose vulnerability profile centers on a single product and skews toward serious severity outcomes. The recurring exposure involves application-layer weaknesses including server-side request forgery, improper query neutralization, open redirects, authorization bypass through user-controlled keys, and cross-site request forgery—typical of web-facing AI and API-driven services where trust boundaries and input handling directly govern data access and remote service invocation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastgpt over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34162CRITICAL FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication | Mar 31, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-40351CRITICAL FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an un | Apr 17, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-40252HIGH FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belon | Apr 10, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-40352HIGH FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "ol | Apr 17, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-33075HIGH FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration b | Mar 20, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-49131CRITICAL FastGPT is an open-source project that provides a platform for building, deploying, and operating AI-driven workflows and conversational agents. The Sandbox container (fastgpt-sand | Jun 9, 2025 | 9.9 | 29 | NO | NO |
CVE-2026-34163HIGH FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTo | Mar 31, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-32128MEDIUM FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes guardrails intended to prevent file writes (static detection + | Mar 11, 2026 | 6.3 | 22 | NO | NO |
CVE-2026-26003MEDIUM FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx without authentication, thereby thre | Feb 10, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-40100MEDIUM FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The internal IP check in is | Apr 10, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastgpt.
Media articles that mention a CVE ID that affects a product developed by Fastgpt — matched by CVE ID, not by vendor name.