CVE-2026-34162Disclosure(fastgpt / fastgpt)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch fastgpt fastgpt systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes a server-side HTTP request and returns the complete response to the caller. This issue has been patched in version 4.14.9.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fastgpt

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-31); latest day: 3
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
fastgpt

Deep dive

Activity timeline7 mentions / 2d
01234Mentions · 2026-03-31: 4Mentions · 2026-04-01: 3PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-03-31: 2Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-31: 4Technical Details · 2026-04-01: 303-3104-01
Signal classification3 categories
Disclosure
342.9%
Patch
342.9%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-314
Disclosure1General1Patch2
2026-04-013
Disclosure2Patch1
Full discourse7 posts
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-34162: FastGPT Unauthenticated HTTP Proxy Enables Full SSRF (CVSS 10.0) https://labs.cosmicbytez.ca/security/cve-2026-34162 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces CVE‑2026‑34162, an unauthenticated HTTP proxy vulnerability that allows full SSRF, providing technical details but no patch or exploit information.

    0002037
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34162: CRITICAL] Warning: FastGPT platform vulnerability detected! Prior to version 4.14.9.5, its HTTP testing endpoint lacks authentication. Update to the latest version to close this security flaw.#cve,CVE-2026-34162,#cybersecurity https://cvefind.com/CVE-2026-34162

    Post summary

    FastGPT’s pre‑4.14.9.5 releases expose an unauthenticated HTTP testing endpoint; the vendor recommends updating to the latest version to remediate the flaw.

    0001046
    617 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34162 FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any … https://www.cve.org/CVERecord?id=CVE-2026-34162

    Post summary

    FastGPT’s HTTP tools endpoint was exposed before version 4.14.9.5; this version’s release fixes the issue, providing an available patch.

    00010102
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34162 - Critical FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This ... https://www.thehackerwire.com/vulnerability/CVE-2026-34162/ https://t.co/H5mzLERQAJ

    Post summary

    FastGPT versions before 4.12.9.5 expose an HTTP tools test endpoint without authentication, creating a critical vulnerability.

    0001027
    163 followersView on X
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2026-34162: FastGPT: Unauthenticated SSRF vi... Perfect SSRF-to-RCE chain: unauthenticated proxy endpoint lets attackers hit internal APIs, steal cloud metadata, and p... https://zerodaysignal.com/vulnerability/CVE-2026-34162 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post references CVE‑2026‑34162, detailing an unauthenticated SSRF that can lead to RCE, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0001062
    194 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical missing authentication in #FastGPT. #CVE-2026-34162 (CVSS: 9.8) allows an unauthenticated attacker to exfiltrate API tokens, access internal services and send arbitrary HTTP-request! See our advisory: https://ccb.belgium.be/advisories/warning-critical-vulnerability-fastgpt-patch-immediately #Patch #Patch #Patch

    Post summary

    FastGPT suffers a critical missing authentication flaw (CVE‑2026‑34162) that enables token exfiltration and arbitrary requests; an advisory urges users to apply the available patch immediately.

    00000266
    7.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34162 | CVSS 10.0 🔴 CVE-2026-34156 | CVSS 9.9 🔴 CVE-2026-34243 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post announces several newly disclosed vulnerabilities with very high CVSS scores, but provides no further details on exploitation, patches, or false positives.

    0000028
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfastgptfastgpt---

Explore more