CRITICAL🇵🇱 Wersja polska

CVE-2026-33075

CVSS 9.4v4.0pub. 2026-03-20upd. 2026-03-23

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out code from the pull request author's fork, then builds and pushes Docker images using attacker-controlled Dockerfiles. This also enables a supply chain attack via the production container registry. A patch was not available at the time of publication.

🤖 AI Analysis
How it works

The fastgpt-preview-image.yml workflow uses the pull_request_target trigger, which executes in the context of the base repository with access to its secrets. Simultaneously, source code is retrieved from the pull request author's fork, meaning an attacker can provide their own malicious Dockerfile. The Docker image building and publishing process is performed using a file controlled by the attacker, allowing execution of arbitrary commands in the CI/CD environment and interception of repository secrets. Additionally, since the built image is pushed to a production container registry, a supply chain attack is possible.

Impact

An attacker can execute arbitrary code in the CI/CD environment, compromise repository secrets (e.g., tokens, API keys), and introduce a malicious image into the production container registry, potentially compromising the entire software supply chain.

Mitigation & patch

At the time of vulnerability publication, a patch was not available. It is recommended to monitor the official FastGPT project repository and security advisory at https://github.com/labring/FastGPT/security/advisories/GHSA-xfx8-w35j-485c for patch availability information. As interim measures, consider restricting pull request submissions from external contributors or disabling the vulnerable workflow until a patch is released.

Who is affected

FastGPT (Fastgpt platform) versions 4.14.8.3 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Fastgpt

    APP
    Fastgpt
    ≤ 4.14.8.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEContainer
CWE
References

Related vulnerabilities

CVE-2026-40351CRITICAL9.8PL ✓same product

NoSQL Injection w FastGPT umożliwia pominięcie uwierzytelnienia

CVE-2026-34162CRITICAL10.0PL ✓same product

FastGPT: nieuwierzytelniony endpoint proxy HTTP umożliwia SSRF

CVE-2026-40352HIGH8.8same product

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulne...

CVE-2026-34163HIGH7.7same product

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) to...

CVE-2026-40252MEDIUM5.3same product

FastGPT to platforma do budowania AI Agent. Przed wersją 4.14.10.4 luka w kontroli dostępu (IDOR/BOLA) pozwala...