FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9.12.
                
            CVSS
                No CVSS.
References
                    Configurations
                    No configuration.
History
                    23 Jun 2025, 20:16
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
21 Jun 2025, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-21 03:15
Updated : 2025-06-23 20:16
NVD link : CVE-2025-52552
Mitre link : CVE-2025-52552
CVE.ORG link : CVE-2025-52552
JSON object : View
Products Affected
                No product.
