Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.27% | — | AgentgptAI | 30/9/2026 | 2/10/2026 | agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Aplazada | Media (6.3) | 0.29% | — | FastgptAI | 22/9/2026 | 25/9/2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a later HTTP connection performs an independent DNS lookup, creating a DNS rebinding… | |
| Aplazada | Media (5.3) | 0.40% | — | Fastgpt Community EditionAI | 31/8/2026 | 1/9/2026 | FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all… | |
| Aplazada | Crítica (9.3) | 0.43% | — | FastgptAI | 28/8/2026 | 9/9/2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result, an unauthenticated attacker who knows a… | |
| Aplazada | Alta (7.5) | 0.50% | — | PentestgptAI | 27/8/2026 | 1/9/2026 | A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials. | |
| Aplazada | Baja (1.3) | 0.37% | — | Greydgl PentestgptAI | 20/8/2026 | 24/8/2026 | A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is associated with this attack. It is… | |
| Aplazada | Baja (2.3) | 0.28% | — | AgentgptAI | 23/7/2026 | 23/7/2026 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look… | |
| Aplazada | Media (5.9) | 0.25% | — | FastgptAI | 15/7/2026 | 20/7/2026 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's private HTTP toolset by using a crafted saved tool id such as http-<victim_toolset_app_id>/<tool_name>. The normal toolset routes deny access, but… | |
| Aplazada | Crítica (9.3) | 0.21% | — | FastgptAI | 15/7/2026 | 15/7/2026 | FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by privileged workflow_run jobs in… | |
| Aplazada | Alta (8.8) | 0.51% | — | FastgptAI | 15/7/2026 | 15/7/2026 | FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official deployment templates. An unauthenticated… | |
| Aplazada | Media (6.3) | 0.36% | — | FastgptAI | 15/7/2026 | 15/7/2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to axios, and axios follows redirects by default. An authenticated workflow user can configure an HTTP request node to call an attacker-controlled… | |
| Aplazada | Alta (7.7) | 0.41% | — | FastgptAI | 15/7/2026 | 15/7/2026 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId center-node lookup is not bound to that authorized context. A low-privileged tenant user can call… | |
| Aplazada | Baja (2.1) | 0.37% | — | Zhayujie Chatgpt-on-wechatAI | 14/7/2026 | 14/7/2026 | A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is… | |
| Aplazada | Alta (8.6) | 0.48% | — | FastgptAI | 7/7/2026 | 9/7/2026 | FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to the caller's team. Because S3 object keys are global within… | |
| Aplazada | Alta (7.7) | 0.52% | — | FastgptAI | 7/7/2026 | 8/7/2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer validates only the top-level URL before passing it to SwaggerParser.bundle, whose remote reference resolver fetches $ref URLs without FastGPT's internal-address guard and returns fetched content inline,… | |
| Aplazada | Alta (7.1) | 0.36% | — | FastgptAI | 7/7/2026 | 8/7/2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without team scoping, allowing any authenticated user to read another team's prompts, retrieved RAG chunks, and completions if… | |
| Aplazada | Media (6.3) | 0.40% | — | FastgptAI | 7/7/2026 | 8/7/2026 | FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in a way that persists a server-owned datasetId value from another tenant. This creates mixed dataset objects and… | |
| Aplazada | Media (5.5) | 0.78% | — | Zhayujie Chatgpt-on-wechatAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 1.3% | — | Zhayujie Chatgpt-on-wechatAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been made… | |
| Aplazada | Media (6.3) | 0.43% | — | FastgptAI | 29/5/2026 | 22/7/2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax accepts a block comment between import and (; the regex matches only ASCII whitespace, and… | |
| Aplazada | Alta (7.7) | 0.36% | — | FastgptAI | 29/5/2026 | 22/7/2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploiting an incomplete… | |
| Aplazada | Baja (1.9) | 1.4% | — | Aandrew-me TgptAI | 9/5/2026 | 24/7/2026 | A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of the component Update Handler. The manipulation leads to command injection. Local access is required to approach this attack. The exploit has… | |
| Aplazada | Baja (2.3) | 0.39% | — | FastgptAI | 8/5/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows attackers (or authenticated users with App editing privileges) to send arbitrary HTTP requests to internal/private network addresses. The fetchData function in the lafModule… | |
| Aplazada | Media (6.3) | 0.40% | — | FastgptAI | 8/5/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The direct MCP preview/run endpoints already rejected internal/private network URLs, but the MCP tool create/update endpoints could still save an internal MCP server URL. That… | |
| Aplazada | Alta (7.7) | 0.36% | — | FastgptAI | 8/5/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a fullUrl.startsWith() check against a hardcoded list. This check can be bypassed using at least 7 different URL encoding… |