top of page
perceptive_background_267k.jpg

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacke…

Published:

16 April 2026 at 22:00:00

Alert date:

17 April 2026 at 23:02:26

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Identity & Access

FastGPT AI Agent building platform contains a critical NoSQL injection vulnerability in versions prior to 4.14.9.5. The vulnerability exists in the password change endpoint where authenticated attackers can bypass old password verification by injecting MongoDB query operators. This allows low-privileged users to change passwords without knowing the current one, potentially leading to full account takeover. The vulnerability can be combined with ID manipulation to target other user accounts. The issue enables persistence and complete account compromise for attackers who have gained initial low-privileged access.

Technical details

Mitigation steps:

Affected products:

FastGPT

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page