vciy

CVEs we hold for Labring

Records whose assigning authority named Labring as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-68929FastGPT: Unauthenticated WeChat channel hijack and denial of service via shareId-only authorizationlabring FastGPT
CVE-2026-61684FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')labring FastGPT
CVE-2026-61646FastGPT: Shared axios SSRF guard validates only the initial URL before following redirectslabring FastGPT
CVE-2026-61644FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId…labring FastGPT
CVE-2026-61643FastGPT: workflow runtime can execute another user's private HTTP toolsetlabring FastGPT
CVE-2026-55418FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)labring FastGPT
CVE-2026-54607FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)labring FastGPT
CVE-2026-54602FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecordlabring FastGPT
CVE-2026-54601FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusionlabring FastGPT
CVE-2026-50562FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflowslabring FastGPT
CVE-2026-44287FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassablelabring FastGPT
CVE-2026-44286FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validationlabring FastGPT
CVE-2026-44285FastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview APIlabring FastGPT
CVE-2026-44284FastGPT: Stored MCP tool URL SSRF in FastGPT workflow executionlabring FastGPT
CVE-2026-42345FastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding…labring FastGPT
CVE-2026-42344FastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpointslabring FastGPT
CVE-2026-42343FastGPT: Uncontrolled Resource Consumption leading to Sandbox Exhaustionlabring FastGPT
CVE-2026-42302FastGPT: Unauthenticated Remote Code Execution (RCE) via code-server Misconfiguration in agent-sandboxlabring FastGPT
CVE-2026-40352FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeoverlabring FastGPT
CVE-2026-40351FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypasslabring FastGPT
CVE-2026-40252Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPTlabring FastGPT
CVE-2026-40100FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP defaultlabring FastGPT
CVE-2026-34163Server-Side Request Forgery via MCP Tools Endpoint in FastGPTlabring FastGPT
CVE-2026-34162FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theftlabring FastGPT
CVE-2026-33075FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymllabring FastGPT
CVE-2026-32128FastGPT Python Sandbox Bypass of File-Write Restrictionlabring FastGPT
CVE-2026-26075Cross-Site Request Forgery (CSRF) in FastGPTlabring FastGPT
CVE-2026-26003FastGPT Plugin forwarding request is not authenticated, posing a serious risk of attacklabring FastGPT
CVE-2025-62612FastGPT File Reading Node SSRF Vulnerabilitylabring FastGPT
CVE-2025-52552FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSSlabring FastGPT
CVE-2025-49131FastGPT Sandbox Vulnerable to Sandbox Bypasslabring FastGPT
CVE-2025-27600FastGPT SSRFlabring FastGPT
CVE-2023-50253laf logs leaklabring laf
CVE-2023-48225Laf env causes sensitive information disclosurelabring laf
CVE-2023-36815Sealos billing system permission control defectlabring sealos
CVE-2023-33190Improperly configured permissions in Sealoslabring sealos

36 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.