FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization has added stricter internal network address detection. This vulnerability is fixed in 4.14.7.
References
| Link | Resource |
|---|---|
| https://github.com/labring/FastGPT/releases/tag/v4.14.7 | Product Release Notes |
| https://github.com/labring/FastGPT/security/advisories/GHSA-g345-7pqp-c395 | Vendor Advisory |
Configurations
History
23 Feb 2026, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| First Time |
Fastgpt
Fastgpt fastgpt |
|
| CPE | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| References | () https://github.com/labring/FastGPT/releases/tag/v4.14.7 - Product, Release Notes | |
| References | () https://github.com/labring/FastGPT/security/advisories/GHSA-g345-7pqp-c395 - Vendor Advisory |
12 Feb 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-12 22:16
Updated : 2026-02-23 16:52
NVD link : CVE-2026-26075
Mitre link : CVE-2026-26075
CVE.ORG link : CVE-2026-26075
JSON object : View
Products Affected
fastgpt
- fastgpt
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
