CVE Feed

    Dashboard / CVE / CVE-2026-40352

    CVE-2026-40352

    FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed in version 4.14.9.5.

    Published:Apr 17, 2026
    Last Modified:Apr 27, 2026
    EPS:Apr 17, 2026
    EPSS Score:0.00032
    CVSS Score:8.8

    Affected Products

    Vendor
    Fastgpt
    Product
    Fastgpt
    Vendor
    Labring
    Product
    Fastgpt

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High