CVE-2026-42302Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The startup script entrypoint.sh initializes code-server with the --auth none flag and binds the service to all network interfaces (0.0.0.0:8080). This configuration allows any user with network access to the port to bypass authentication and gain full control over the sandbox environment. This issue has been patched in version 4.14.13.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-09); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-05-09: 2Mentions · 2026-05-13: 2Mentions · 2026-06-17: 2Mentions · 2026-06-19: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-13: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-19: 105-0905-1306-1706-19
Signal classification2 categories
Disclosure
571.4%
General
228.6%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure2
2026-05-132
General2
2026-06-172
Disclosure2
2026-06-191
Disclosure1
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    In the last 72 hours, researchers have disclosed critical vulnerabilities in three major agentic frameworks: CVE-2026-25592 & CVE-2026-26030 (Semantic Kernel): Prompt injection RCE CVE-2026-42302 (FastGPT): Agent runtime sandbox escape CVE-2026-44895 (GitLab MCP Server):…

    Post summary

    Researchers have disclosed four critical vulnerabilities in three agentic frameworks—two in Semantic Kernel (prompt injection leading to RCE) and one in FastGPT (runtime sandbox escape)—without providing PoC, exploit tools, or patch information.

    1000050
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources TheHackerWire: FastGPT agent-sandbox RCE (CVE-2026-42302) GitHub Advisory Database The Sandbox Trap: FastGPT Agent RCE Exposes Why AI Agent Platforms Need Runtime Security

    Post summary

    FastGPT’s agent sandbox was identified as having a remote code execution flaw (CVE-2026-42302). The post does not provide evidence of exploitation, PoC, or mitigation steps.

    1000067
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CVE-2026-42302, a critical unauthenticated RCE in FastGPT's agent-sandbox component (CVSS 9.8), allows attackers to gain full code-server access by simply connecting to port 8080. The flaw—launching code-server with --auth none—affects versions 4.14.10 through…

    Post summary

    The excerpt announces CVE-2026-42302, a critical unauthenticated remote code execution vulnerability in FastGPT’s agent-sandbox, detailing the mechanism, CVSS score, and affected versions.

    1000053
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-42302 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post references CVE-2026-42302 with a high CVSS score and critical severity but provides no PoC, exploit details, mitigation, or evidence of exploitation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42302-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text offers only a URL and hashtags, providing no substantive details about CVE-2026-42302 beyond its mention.

    0000020
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42302 FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remo… https://www.cve.org/CVERecord?id=CVE-2026-42302

    Post summary

    FastGPT’s agent‑sandbox component between versions 4.12.10 and 4.14.13 is vulnerable to unauthenticated remote exploitation, but no PoC, active exploitation, patch, or false‑positive claim is mentioned.

    0000085
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42302 Unauthenticated Remote Code Execution in FastGPT Agent-Sandbox 4.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42302 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑42302, noting an unauthenticated remote code execution flaw in FastGPT Agent‑Sandbox 4, and links to a vulnerability detail page for further information.

    0000060
    4.0K followersView on X

Explore more