
CVE-2026-40100 FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The internal … https://www.cve.org/CVERecord?id=CVE-2026-40100
Post summary
This post discloses a CVE-2026-40100 vulnerability in FastGPT that allows unauthenticated arbitrary URL execution via a specific endpoint before a certain version, but it includes neither a PoC, exploit code, nor evidence of active exploitation.
