CVE-2025-62612: FastGPT File Reading Node SSRF Vulnerability
FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62612?
CVE-2025-62612 is classified as a high severity vulnerability due to the risk of server-side request forgery (SSRF) attacks.
How do I fix CVE-2025-62612?
To fix CVE-2025-62612, upgrade FastGPT to version 4.11.1 or later, where the vulnerability has beenpatched.
What is the impact of CVE-2025-62612 on FastGPT?
CVE-2025-62612 can allow an attacker to perform SSRF attacks by exploiting unverified network links in the workflow file reading node.
What versions of FastGPT are affected by CVE-2025-62612?
CVE-2025-62612 affects all versions of FastGPT prior to version 4.11.1.
Is there a known exploit for CVE-2025-62612?
As of now, there are no publicly known exploits specifically targeting CVE-2025-62612, but it is advisable to mitigate the risk by applying the patch.