Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting labring.
- CVE-2026-61643FastGPT: workflow runtime can execute another user's private HTTP toolset5.9
- CVE-2026-61644FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup7.7
- CVE-2026-54607FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)7.7
- CVE-2026-55418FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)8.6
- CVE-2026-54601FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion6.3
- CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable6.3
- CVE-2026-44285FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API7.7
- CVE-2026-44284FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution6.3
- CVE-2026-42345FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot7.7
- CVE-2026-42344FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpoints6.3
- CVE-2026-42302FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox9.8
- CVE-2026-40352FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover8.8
- CVE-2026-40351FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass9.8
- CVE-2026-40252Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT8.1
- CVE-2026-40100FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default5.3