CVE-2025-52552: FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSS
FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9.12.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52552?
CVE-2025-52552 has been classified as a high severity vulnerability due to its potential to allow open redirects and DOM-based XSS.
How do I fix CVE-2025-52552?
To fix CVE-2025-52552, update FastGPT to version 4.9.12 or later, which addresses the vulnerabilities related to the LastRoute parameter.
What type of vulnerabilities are associated with CVE-2025-52552?
CVE-2025-52552 is associated with open redirect and DOM-based XSS vulnerabilities due to improper validation of the LastRoute parameter.
What are the risks of CVE-2025-52552?
Exploitation of CVE-2025-52552 can lead to unauthorized redirects and execution of malicious JavaScript in user browsers.
Who is affected by CVE-2025-52552?
CVE-2025-52552 affects all users of FastGPT versions prior to 4.9.12.