CVE-2026-33075Disclosure(fastgpt / fastgpt)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out code from the pull request author's fork, then builds and pushes Docker images using attacker-controlled Dockerfiles. This also enables a supply chain attack via the production container registry. A patch was not available at the time of publication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-494CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastgpt

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
fastgpt

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure1General1
2026-03-221
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33075 FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret … https://www.cve.org/CVERecord?id=CVE-2026-33075

    Post summary

    FastGPT versions 4.14.8.3 and below have a workflow that allows arbitrary code execution and secret exposure, but no PoC, exploit, active use, or patch information is disclosed.

    00000128
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33075 Arbitrary Code Execution in FastGPT CI/CD Workflow via Pull Request Targ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33075 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE-2026-33075, noting it enables arbitrary code execution in FastGPT’s CI/CD workflow via a pull request target, but offers no proof‑of‑concept, exploitation methods, or patch information.

    0000039
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33075: FastGPT has Arbitrary Code Execu... pull_request_target + attacker-controlled Dockerfiles = instant repo takeover and secret theft - classic GitHub Actions... https://zerodaysignal.com/vulnerability/CVE-2026-33075 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑33075, outlining an arbitrary code execution flaw in FastGPT via attacker‑controlled Dockerfiles in GitHub Actions, without providing PoC, exploit tooling, active exploitation evidence, or remediation details.

    0000070
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastgptfastgpt---

Explore more