NoSQL Injection Vulnerability in FastGPT AI Agent Building Platform
CVE-2026-40351
9.8CRITICAL
What is CVE-2026-40351?
FastGPT, an AI Agent building platform by labring, contains a NoSQL injection vulnerability in its password-based login endpoint prior to version 4.14.9.5. This flaw arises from the use of TypeScript type assertion without adequate runtime validation, which allows an unauthenticated attacker to exploit the password field by submitting a MongoDB query operator object. As a result, the password check can be bypassed, granting unauthorized access to user accounts, including elevated privileges for the root administrator. The vulnerability has been addressed in the release of version 4.14.9.5.
Affected Version(s)
FastGPT < 4.14.9.5
