Arbitrary Command Execution Vulnerability in FastGPT AI Agent Platform
CVE-2026-44287
6.3MEDIUM
What is CVE-2026-44287?
FastGPT, an AI Agent building platform, has a vulnerability that permits arbitrary command execution via a flaw in its JavaScript sandbox. The issue arises from the inadequate filtering of dynamic imports, allowing attackers to exploit this gap by executing malicious code. The JavaScript sandbox does not properly handle dynamic import statements with block comments, enabling crafted payloads to bypass security measures. This results in the unauthorized execution of commands in the sandbox environment, impacting the integrity and security of the application. The vulnerability has been resolved in version 4.15.0-beta1.
Affected Version(s)
FastGPT < 4.15.0-beta1
