Open Redirect and DOM-Based XSS in FastGPT Platform by LabRing
CVE-2025-52552
5.5MEDIUM
What is CVE-2025-52552?
The FastGPT AI Agent building platform has a vulnerability where the LastRoute parameter on the login page allows for open redirection and DOM-based XSS. This is caused by improper validation and lack of sanitization of user input, enabling attackers to execute malicious JavaScript or redirect users to sites controlled by attackers. This security issue has been addressed in version 4.9.12.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FastGPT < 4.9.12
References
CVSS V4
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
