CVE-2026-42345Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a fullUrl.startsWith() check against a hardcoded list. This check can be bypassed using at least 7 different URL encoding techniques, all of which resolve to the same cloud metadata service but do not match the blocklist patterns. Additionally, the broader private IP check (isInternalIPv4/isInternalIPv6) is disabled by default because CHECK_INTERNAL_IP defaults to false (not 'true'), so these bypasses reach the metadata endpoint without any further validation. At time of publication, there are no publicly available patches.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-09: 2Technical Details · 2026-05-09: 205-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42345 FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks clou… https://www.cve.org/CVERecord?id=CVE-2026-42345

    Post summary

    CVE‑2026‑42345 discloses an issue in FastGPT's isInternalAddress() function affecting versions 4.14.11 and prior, but no exploit or patch details are present.

    0000076
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42345 Cloud Metadata Endpoint Access Bypass in FastGPT 4.14.11 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42345

    Post summary

    The tweet announces CVE-2026-42345, a Cloud Metadata Endpoint access bypass in FastGPT versions 4.14.11 and earlier, without providing a PoC, exploit, or mitigation.

    0000037
    4.0K followersView on X

Explore more