NoSQL Injection Vulnerability in FastGPT AI Agent Building Platform
CVE-2026-40351

9.8CRITICAL

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
17 April 2026

What is CVE-2026-40351?

FastGPT, an AI Agent building platform by labring, contains a NoSQL injection vulnerability in its password-based login endpoint prior to version 4.14.9.5. This flaw arises from the use of TypeScript type assertion without adequate runtime validation, which allows an unauthenticated attacker to exploit the password field by submitting a MongoDB query operator object. As a result, the password check can be bypassed, granting unauthorized access to user accounts, including elevated privileges for the root administrator. The vulnerability has been addressed in the release of version 4.14.9.5.

Affected Version(s)

FastGPT < 4.14.9.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.