CVE-2025-62612

Severity CVSS v4.0:
MEDIUM
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
22/10/2025
Last modified:
29/12/2025

Description

FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* 4.11.1 (excluding)