CVE-2026-40352

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed in version 4.14.9.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:*

History

27 Apr 2026, 19:39

Type Values Removed Values Added
CPE cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:*
References () https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d - () https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d - Patch
References () https://github.com/labring/FastGPT/releases/tag/v4.14.9.5 - () https://github.com/labring/FastGPT/releases/tag/v4.14.9.5 - Product, Release Notes
References () https://github.com/labring/FastGPT/security/advisories/GHSA-422w-vrfj-72g6 - () https://github.com/labring/FastGPT/security/advisories/GHSA-422w-vrfj-72g6 - Exploit, Vendor Advisory
First Time Fastgpt
Fastgpt fastgpt

17 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 22:16

Updated : 2026-04-27 19:39


NVD link : CVE-2026-40352

Mitre link : CVE-2026-40352

CVE.ORG link : CVE-2026-40352


JSON object : View

Products Affected

fastgpt

  • fastgpt
CWE
CWE-943

Improper Neutralization of Special Elements in Data Query Logic