CVE-2026-34162

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
31/03/2026
Last modified:
01/04/2026

Description

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes a server-side HTTP request and returns the complete response to the caller. This issue has been patched in version 4.14.9.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* 4.14.9.5 (excluding)