HIGH🇵🇱 Wersja polska

CVE-2026-40352

CVSS 8.8v3.1pub. 2026-04-17upd. 2026-04-27

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed in version 4.14.9.5.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Fastgpt

    APP
    Fastgpt
    < 4.14.9.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-40351CRITICAL9.8PL ✓same product

NoSQL Injection w FastGPT umożliwia pominięcie uwierzytelnienia

CVE-2026-34162CRITICAL10.0PL ✓same product

FastGPT: nieuwierzytelniony endpoint proxy HTTP umożliwia SSRF

CVE-2026-33075CRITICAL9.4PL ✓same product

FastGPT: RCE i eksfiltracja sekretów przez złośliwy Dockerfile w workflow CI/CD

CVE-2026-34163HIGH7.7same product

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) to...

CVE-2026-40100MEDIUM5.3same product

FastGPT to platforma do budowania AI Agent. Przed wersją 4.14.10.3 endpoint /api/core/app/mcpTools/runTool akc...