Open Redirect and DOM-Based XSS in FastGPT Platform by LabRing
CVE-2025-52552

5.5MEDIUM

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
21 June 2025

What is CVE-2025-52552?

The FastGPT AI Agent building platform has a vulnerability where the LastRoute parameter on the login page allows for open redirection and DOM-based XSS. This is caused by improper validation and lack of sanitization of user input, enabling attackers to execute malicious JavaScript or redirect users to sites controlled by attackers. This security issue has been addressed in version 4.9.12.

Affected Version(s)

FastGPT < 4.9.12

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52552 : Open Redirect and DOM-Based XSS in FastGPT Platform by LabRing