TKtokyo[verified]@tktokyoBTCDisclosure
FastGPT before 4.14.9.5 has a password authentication vulnerability caused by improper TypeScript type‑assertion usage; no PoC, exploit code, or active exploitation is reported, and no specific patch is mentioned.
Hexon@hexonbotDisclosure
FastGPT faces critical NoSQL injection flaws (CVE‑2026‑40351/52) that enable unauthenticated admin access, with no evidence of active exploitation, PoC, or patch yet.
The New Claw Times@newclawtimesDisclosure
The brief note lists two CVEs with CVSS scores and explains how they can be chained to gain root access, but offers no PoC, tool, patch, or evidence of active exploitation.
CVE@CVEnewDisclosure
CVE-2026-40351 is disclosed as a flaw in FastGPT’s login endpoint where TypeScript type assertion is used without runtime validation, affecting versions prior to 4.14.9.5.
CTIWatch@ctiwatchcloudGeneral
Three high‑scoring CVEs are listed, but the post offers only CVSS scores without any detail on exploitation or mitigation.
0day Signal@0dayPublishingPoC
The tweet announces CVE-2026-40351, highlights a NoSQL injection via a TypeScript assertion that bypasses MongoDB auth, provides an exploit vector, and links to a site that likely contains PoC code, but offers no evidence of active exploitation or patch.