CVE-2026-40351

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. This issue has been fixed in version 4.14.9.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:*

History

27 Apr 2026, 19:39

Type Values Removed Values Added
CPE cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:*
First Time Fastgpt
Fastgpt fastgpt
References () https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d - () https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d - Patch
References () https://github.com/labring/FastGPT/releases/tag/v4.14.9.5 - () https://github.com/labring/FastGPT/releases/tag/v4.14.9.5 - Product, Release Notes
References () https://github.com/labring/FastGPT/security/advisories/GHSA-x8mx-2mr7-h9xg - () https://github.com/labring/FastGPT/security/advisories/GHSA-x8mx-2mr7-h9xg - Exploit, Mitigation, Vendor Advisory

17 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 22:16

Updated : 2026-04-27 19:39


NVD link : CVE-2026-40351

Mitre link : CVE-2026-40351

CVE.ORG link : CVE-2026-40351


JSON object : View

Products Affected

fastgpt

  • fastgpt
CWE
CWE-943

Improper Neutralization of Special Elements in Data Query Logic