Unauthenticated HTTP Proxy Vulnerability in FastGPT AI Agent Platform
CVE-2026-34162

10CRITICAL

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34162?

FastGPT, an AI Agent building platform, exposed a critical endpoint prior to version 4.14.9.5 that allowed unauthenticated users to invoke the HTTP tools testing endpoint. This vulnerability permitted the sending of arbitrary HTTP requests to any URL specified by the user, bypassing authentication mechanisms. The endpoint functioned as a full HTTP proxy, meaning attackers could leverage it to access sensitive data or services without authorization. The issue has been addressed in version 4.14.9.5, which secures the endpoint against unauthorized access.

Affected Version(s)

FastGPT < 4.14.9.5

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.