
FastGPT hit by critical NoSQL injection vulnerabilities enabling unauthenticated admin access. CVE-2026-40351 and CVE-2026-40352 threaten AI agent platforms. https://www.hexon.bot/blog/fastgpt-nosql-injection-ai-agent-security-2026 #AISecurity #FastGPT #CVE
Post summary
FastGPT has been reported to contain two critical NoSQL injection CVEs (CVE‑2026‑40351 and CVE‑2026‑40352) that enable unauthenticated admin access, with details published on Hexon bot's blog; no exploit codes, remediation or active exploitation claims are provided.


