CVE-2026-26075 PUBLISHED

Cross-Site Request Forgery (CSRF) in FastGPT

Assigner: GitHub_M
Reserved: 10.02.2026 Published: 12.02.2026 Updated: 12.02.2026

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization has added stricter internal network address detection. This vulnerability is fixed in 4.14.7.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor labring
Product FastGPT
Versions
  • Version < 4.14.7 is affected

References

Problem Types

  • CWE-352: Cross-Site Request Forgery (CSRF) CWE