CVE 7.7 HIGH

FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview API_CVE-2026-44285

7.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Description

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploiting an incomplete fix in the dataset preview endpoint /api/core/dataset/file/getPreviewChunks when utilizing the externalFile data import type. This vulnerability is fixed in 4.15.0-beta1.

Basic Information

ID CVE-2026-44285
Source GitHub_M
Published May 29, 2026 at 19:32

Affected Product

Vendor labring
Product FastGPT
Version < 4.15.0-beta1
Affected Versions labring FastGPT < 4.15.0-beta1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.