Open Redirect and DOM-Based XSS in FastGPT Platform by LabRing
CVE-2025-52552
5.5MEDIUM
What is CVE-2025-52552?
The FastGPT AI Agent building platform has a vulnerability where the LastRoute parameter on the login page allows for open redirection and DOM-based XSS. This is caused by improper validation and lack of sanitization of user input, enabling attackers to execute malicious JavaScript or redirect users to sites controlled by attackers. This security issue has been addressed in version 4.9.12.
Affected Version(s)
FastGPT < 4.9.12