HTTP Nodes Vulnerability in FastGPT AI Agent Building Platform
CVE-2026-26075

6.9MEDIUM

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
12 February 2026

What is CVE-2026-26075?

The FastGPT platform, designed for building AI agents, has vulnerabilities related to its HTTP nodes and data acquisition mechanisms. These security concerns arise because the platform requires initiating data requests from the server, potentially exposing internal network information. To mitigate these risks, it is essential to implement strict network isolation in deployment environments, alongside employing enhanced internal network address detection. The issue has been resolved in FastGPT version 4.14.7, emphasizing the importance of updating to maintain security.

Affected Version(s)

FastGPT < 4.14.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.