CVE-2026-34162
FastGPT’s HTTP tools testing endpoint was exposed without authentication before version 4.14.9.5, allowing anyone on the network to use it as an HTTP proxy. The vulnerability has been fixed in the 4.14.9.5 release. Users should update to this version or later to eliminate the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
FastGPT platform, specifically versions earlier than 4.14.9.5. Developers and teams using FastGPT’s HTTP tools testing endpoint are affected.
Real-world impact
An attacker can send arbitrary HTTP requests from the FastGPT server to any target, potentially accessing internal resources, exfiltrating data, or performing malicious actions without needing credentials.
Why this severity
The CVSS score of 10 reflects that the flaw is exploitable over the network (AV:N), requires no authentication (PR:N) or user interaction (UI:N), and changes the system’s security scope (S:C). It grants high confidentiality and integrity impact, while availability impact is low, leading to the maximum score.
What to do about it
- 01Upgrade FastGPT to version 4.14.9.5 or later.
NVD-referenced vendor advisory
Timeline
- Mar 31, 2026 · Mar 31, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/labring/FastGPT/commit/bc7e…patch
- github.com/labring/FastGPT/pull/6640issue trackingpatch
- github.com/labring/FastGPT/releases/ta…productrelease notes
- github.com/labring/FastGPT/security/ad…exploitmitigationvendor advisory