FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. This issue has been fixed in version 4.14.9.5.
References
| Link | Resource |
|---|---|
| https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d | Patch |
| https://github.com/labring/FastGPT/releases/tag/v4.14.9.5 | Product Release Notes |
| https://github.com/labring/FastGPT/security/advisories/GHSA-x8mx-2mr7-h9xg | Exploit Mitigation Vendor Advisory |
Configurations
History
27 Apr 2026, 19:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* | |
| First Time |
Fastgpt
Fastgpt fastgpt |
|
| References | () https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d - Patch | |
| References | () https://github.com/labring/FastGPT/releases/tag/v4.14.9.5 - Product, Release Notes | |
| References | () https://github.com/labring/FastGPT/security/advisories/GHSA-x8mx-2mr7-h9xg - Exploit, Mitigation, Vendor Advisory |
17 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-17 22:16
Updated : 2026-04-27 19:39
NVD link : CVE-2026-40351
Mitre link : CVE-2026-40351
CVE.ORG link : CVE-2026-40351
JSON object : View
Products Affected
fastgpt
- fastgpt
CWE
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
