CVE-2026-34162
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes a server-side HTTP request and returns the complete response to the caller. This issue has been patched in version 4.14.9.5.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
- EPSS probability
- 0.42%
- CWE
- CWE-306, CWE-918
- Published
- 2026-03-31
- Last modified
- 2026-03-31
Affected products
- labring FastGPT
Weakness type
Related vulnerabilities
- CVE-2026-77974 — Softish C6 Ear Camera and EarVision Android Application Missing authentication for critical function
- CVE-2026-79961 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-11838 — Improper Authorization in Yordam Informatics' Library Reservation System
- CVE-2026-85981 — Unauthenticated Localhost Admin Panel in Auth0 AD/LDAP Connector
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-86808 — moltis-org moltis vault.rs vault_recovery_handler missing authentication
- CVE-2026-73004 — Windows Autopilot Tampering Vulnerability
- CVE-2026-72964 — Windows Internet Connection Sharing (ICS) Tampering Vulnerability