top of page
perceptive_background_267k.jpg

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass t…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

FastGPT AI Agent building platform contains a Server-Side Request Forgery (SSRF) vulnerability prior to version 4.15.0-beta1. The vulnerability allows authenticated attackers to bypass network protection and make arbitrary HTTP GET requests to internal network services. The issue stems from an incomplete fix in the dataset preview endpoint /api/core/dataset/file/getPreviewChunks when using the externalFile data import type. Attackers can exploit this to access internal network services that should be protected. The vulnerability has been fixed in version 4.15.0-beta1.

Technical details

Mitigation steps:

Affected products:

FastGPT

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page