github TypeScript not analyzable

labring/FastGPT

github

not analyzable — repository too large to download in full

FastGPT is a knowledge-based platform built on the LLMs, offers a comprehensive suite of out-of-the-box capabilities such as data processing, RAG retrieval, and visual AI workflow orchestration, letting you easily develop and deploy complex question-answering systems without the need for extensive setup or configuration.

maintainer
labring
license
NOASSERTION
first seen
2026-05-22
last seen
2026-07-31
releases · 30d
6
short id
risk 77/100 · heuristic grade
D high

Source not yet analyzed — this grade rests on attested signals (CVEs, supply-chain) only. It is a floor: reading the code could raise it, not lower it.

  • vulnerabilities attested + 50
  • capability exposure inferred + 35
  • trust mitigators mixed − 8

attested inferred mixed

The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.

graded 6m ago · see ecosystem CVEs →

risk trajectory 3 movements
  • B · 27 D · 77
  • C · 39 B · 27
  • A · 0 C · 39
capability exposure grade factor +35
Inferred surface — each links to servers holding it:
vulnerabilities 20 CVEs · grade factor +50
CRITICAL
Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandbox EPSS 1% CVE-2026-42302 affects ["4.14.10~4.14.12"]
CRITICAL
NoSQL Injection in loginByPassword leads to Authentication Bypass EPSS 1% CVE-2026-40351 affects ["<4.14.9.5"]
CRITICAL
Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml EPSS 0% CVE-2026-33075 affects ["<4.14.8.4"]
CRITICAL
The Plugin forwarding request is not authenticated, posing a serious risk of attack EPSS 0% CVE-2026-26003 affects ["v4.14.0~v4.14.5"]
HIGH
S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure … EPSS 0% CVE-2026-55418 affects ["<4.15.0-beta5"]
HIGH
SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress gua … EPSS 0% CVE-2026-54607 affects ["4.15.0-4 (HEAD ecc45a58)"]
HIGH
FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an u … EPSS 0% CVE-2026-61644 affects ["4.14.17~4.14.23"]
HIGH
Python Code-Sandbox Escape to OS Command Execution via __subclasses__ AST-Check Bypass in FastGPT affects ["<= 4.15.0-4"]
HIGH
SSRF Protection Bypass via `externalFile` in Dataset Preview API EPSS 0% CVE-2026-44285 affects ["<= 4.15.0-beta1"]
HIGH
Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP … EPSS 0% CVE-2026-42345 affects ["<= 4.14.11"]
HIGH
NoSQL Injection in updatePasswordByOld leads to Account Takeover EPSS 0% CVE-2026-40352 affects ["<4.14.9.5"]
LOW
Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord EPSS 0% CVE-2026-54602 affects ["current (HEAD 58254a4)"]
MEDIUM
FastGPT: workflow runtime can execute another user's private HTTP toolset EPSS 0% CVE-2026-61643 affects [">= 4.14.17, <= 4.14.23 = 4.15.0-beta3"]
MEDIUM
FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorizat … EPSS 0% CVE-2026-54601 affects ["4.14.17~4.14.23"]
MEDIUM
Shared axios SSRF guard validates only the initial URL before following redirects EPSS 0% CVE-2026-61646 affects ["< 4.15.0"]
LOW
Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRE … EPSS 0% CVE-2026-61684 affects ["<= 4.15.0"]
MEDIUM
Untrusted PR artifacts are pushed and deployed by privileged preview workflows EPSS 0% CVE-2026-50562 affects ["<= 22ebfacbb43311e9b73294040ae0eb87390c6bba"]
MEDIUM
sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable EPSS 0% CVE-2026-44287 affects ["<= 4.15.0-beta1"]
LOW
SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation EPSS 0% CVE-2026-44286 affects ["<= 4.14.17"]
MEDIUM
Stored MCP tool URL SSRF in FastGPT workflow execution EPSS 0% CVE-2026-44284 affects ["<= 4.14.16"]
tool safety all quiet

No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.

embed badge readme-ready
live risk-grade badge preview [![MCP Observatory risk grade](https://mcpobservatory.com/servers/github:labring/FastGPT/badge.svg)](https://mcpobservatory.com/servers/github:labring/FastGPT/security)

Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of labring.