


Perceptive Security
SOC/SIEM Consultancy

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacke…
Published:
16 april 2026 om 22:00:00
Alert date:
17 april 2026 om 23:02:26
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Identity & Access
FastGPT AI Agent building platform contains a critical NoSQL injection vulnerability in versions prior to 4.14.9.5. The vulnerability exists in the password change endpoint where authenticated attackers can bypass old password verification by injecting MongoDB query operators. This allows low-privileged users to change passwords without knowing the current one, potentially leading to full account takeover. The vulnerability can be combined with ID manipulation to target other user accounts. The issue enables persistence and complete account compromise for attackers who have gained initial low-privileged access.
Technical details
Mitigation steps:
Affected products:
FastGPT
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40352
https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d
https://github.com/labring/FastGPT/releases/tag/v4.14.9.5
https://github.com/labring/FastGPT/security/advisories/GHSA-422w-vrfj-72g6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
