216.73.217.22

CVE-2026-40351

· Published 17/04/2026 22:16 · Modified 17/04/2026 22:16

Labels: CVE-2026-40351 2026-04-17CVE-2026-40351CWE-943[email protected]

Essential information

Published
17/04/2026 22:16
Modified
17/04/2026 22:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. This issue has been fixed in version 4.14.9.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fastgpt / fastgpt cpe:2.3:a:fastgpt:fastgpt:<4.14.9.5:*:*:*:*:*:*:*

References