DNS Rebinding Vulnerability in FastGPT Open-Source AI Platform
CVE-2026-84301

6.3MEDIUM

Key Information:

Vendor

Labring

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-84301?

FastGPT, an open-source large language model (LLM) platform for AI applications, has a DNS rebinding vulnerability prior to version 4.15.2. This issue arises because the Axios request interceptor in the application does not adequately validate hostnames, creating a window wherein an attacker can exploit a time-of-check/time-of-use gap. An authenticated attacker leveraging this vulnerability can craft a malicious hostname that resolves first to a public address and subsequently to a private or link-local address, thereby bypassing security measures and accessing services that are otherwise protected. This vulnerability is addressed in version 4.15.2, which enhances hostname validation during HTTP requests and connection establishment.

Affected Version(s)

FastGPT < 4.15.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.