FastGPT
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 25 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 6, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →FastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requests
FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')
FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)
FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion
FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable
FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API
FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation
FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution
FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dot
FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustion
Monitor FastGPT in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.