Arbitrary Command Execution Vulnerability in FastGPT AI Agent Platform
CVE-2026-44287

6.3MEDIUM

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-44287?

FastGPT, an AI Agent building platform, has a vulnerability that permits arbitrary command execution via a flaw in its JavaScript sandbox. The issue arises from the inadequate filtering of dynamic imports, allowing attackers to exploit this gap by executing malicious code. The JavaScript sandbox does not properly handle dynamic import statements with block comments, enabling crafted payloads to bypass security measures. This results in the unauthorized execution of commands in the sandbox environment, impacting the integrity and security of the application. The vulnerability has been resolved in version 4.15.0-beta1.

Affected Version(s)

FastGPT < 4.15.0-beta1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.