216.73.217.22

CVE-2026-33075

· Published 20/03/2026 09:16 · Modified 20/03/2026 13:37

Labels: CVE-2026-33075 2026-03-20CVE-2026-33075CWE-494[email protected]

Essential information

Published
20/03/2026 09:16
Modified
20/03/2026 13:37
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out code from the pull request author's fork, then builds and pushes Docker images using attacker-controlled Dockerfiles. This also enables a supply chain attack via the production container registry. A patch was not available at the time of publication.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fastgpt / fastgpt cpe:2.3:a:fastgpt:fastgpt:<4.14.8.3:*:*:*:*:*:*:*

References