FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization has added stricter internal network address detection. This vulnerability is fixed in 4.14.7.
References
| Link | Resource |
|---|---|
| https://github.com/labring/FastGPT/releases/tag/v4.14.7 | Product Release Notes |
| https://github.com/labring/FastGPT/security/advisories/GHSA-g345-7pqp-c395 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-02-12 22:16
Updated : 2026-02-23 16:52
NVD link : CVE-2026-26075
Mitre link : CVE-2026-26075
CVE.ORG link : CVE-2026-26075
JSON object : View
Products Affected
fastgpt
- fastgpt
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
