CVE 8.8 HIGH

FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover_CVE-2026-40352

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed in version 4.14.9.5.

AI Analysis

NoSQL injection vulnerability in the password change endpoint, allowing authenticated attackers to bypass old password verification and take over accounts.

Basic Information

ID CVE-2026-40352
Source GitHub_M
Published Apr 17, 2026 at 21:09

Affected Product

Vendor labring
Product FastGPT
Version < 4.14.9.5
Affected Versions labring FastGPT < 4.14.9.5

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor labring
Product FastGPT
Version < 4.14.9.5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.