CVE-2026-61643

MEDIUM CVSS 3.1: 5.9 EPSS 0.25%
Updated Jul 20, 2026
Fastgpt
Parameter Value
CVSS 5.9 (MEDIUM)
Fixed In 4.15.0
Type CWE-863 (Incorrect Authorization)
Vendor Fastgpt
Public PoC No

FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's private HTTP toolset by using a crafted saved tool id such as http-<victim_toolset_app_id>/<tool_name>. The normal toolset routes deny access, but the workflow save and runtime path did not apply the same authorization check to the referenced toolset, allowing /api/v2/chat/completions to resolve the saved reference and execute the victim-owned HTTP tool.

This issue is fixed in version 4.15.0-beta5.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1