


Perceptive Security
SOC/SIEM Consultancy

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass t…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 21:09:42
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
FastGPT AI Agent building platform contains a Server-Side Request Forgery (SSRF) vulnerability prior to version 4.15.0-beta1. The vulnerability allows authenticated attackers to bypass network protection and make arbitrary HTTP GET requests to internal network services. The issue stems from an incomplete fix in the dataset preview endpoint /api/core/dataset/file/getPreviewChunks when using the externalFile data import type. Attackers can exploit this to access internal network services that should be protected. The vulnerability has been fixed in version 4.15.0-beta1.
Technical details
Mitigation steps:
Affected products:
FastGPT
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44285
https://github.com/labring/FastGPT/security/advisories/GHSA-c65v-7vx6-f8m3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
