SSRF Vulnerability in FastGPT AI Agent Building Platform
CVE-2025-62612

6.9MEDIUM

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
22 October 2025

What is CVE-2025-62612?

The FastGPT AI Agent building platform contains a vulnerability that allows for Server-Side Request Forgery (SSRF) attacks. Before version 4.11.1, the platform's workflow file reading node did not adequately verify network links, enabling potential attackers to manipulate and access internal resources through crafted requests. This issue has significant implications for organizations relying on FastGPT, emphasizing the importance of updating to version 4.11.1 or later to mitigate these risks.

Affected Version(s)

FastGPT < 4.11.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62612 : SSRF Vulnerability in FastGPT AI Agent Building Platform