CVE-2026-44284
FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The direct MCP preview/run endpoints already rejected internal/private network URLs, but the MCP tool create/update endpoints could still save an internal MCP server URL. That stored URL could later be used by workflow execution without revalidating the destination. An authenticated user with permission to create or manage MCP toolsets could store an internal endpoint such as http://localhost:3000/mcp and later cause the FastGPT backend workflow runner to connect to that internal destination. This issue has been patched in version 4.14.17.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Puntuación base: 6.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-918
Referencias
- https://github.com/labring/FastGPT/commit/c1c6b9520d976d25ed945b5bc4e0768149e6db69
- https://github.com/labring/FastGPT/pull/6826
- https://github.com/labring/FastGPT/releases/tag/v4.14.17
- https://github.com/labring/FastGPT/security/advisories/GHSA-cxxj-99f7-f5wq
- https://github.com/labring/FastGPT/pull/6826
- https://github.com/labring/FastGPT/security/advisories/GHSA-cxxj-99f7-f5wq
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-44284",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-44284",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-11T15:57:46.900457Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "labring",
"product": "FastGPT",
"versions": [
{
"status": "affected",
"version": "< 4.14.17"
}
]
}
]
}
],
"published": "2026-05-08T23:16:39.507",
"references": [
{
"url": "https://github.com/labring/FastGPT/commit/c1c6b9520d976d25ed945b5bc4e0768149e6db69",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/labring/FastGPT/pull/6826",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/labring/FastGPT/releases/tag/v4.14.17",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/labring/FastGPT/security/advisories/GHSA-cxxj-99f7-f5wq",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/labring/FastGPT/pull/6826",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
},
{
"url": "https://github.com/labring/FastGPT/security/advisories/GHSA-cxxj-99f7-f5wq",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-918"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The direct MCP preview/run endpoints already rejected internal/private network URLs, but the MCP tool create/update endpoints could still save an internal MCP server URL. That stored URL could later be used by workflow execution without revalidating the destination. An authenticated user with permission to create or manage MCP toolsets could store an internal endpoint such as http://localhost:3000/mcp and later cause the FastGPT backend workflow runner to connect to that internal destination. This issue has been patched in version 4.14.17."
},
{
"lang": "es",
"value": "FastGPT es una plataforma de creación de agentes de IA. Antes de la versión 4.14.17, FastGPT tenía una brecha de protección SSRF inconsistente en el manejo de URL de herramientas MCP. Los puntos finales directos de vista previa/ejecución de MCP ya rechazaban las URL de red interna/privada, pero los puntos finales de creación/actualización de herramientas MCP aún podían guardar una URL de servidor MCP interna. Esa URL almacenada podría ser utilizada más tarde por la ejecución del flujo de trabajo sin revalidar el destino. Un usuario autenticado con permiso para crear o administrar conjuntos de herramientas MCP podría almacenar un punto final interno como http://localhost:3000/mcp y más tarde hacer que el ejecutor de flujos de trabajo de backend de FastGPT se conectara a ese destino interno. Este problema ha sido parcheado en la versión 4.14.17."
}
],
"lastModified": "2026-07-24T20:10:00.147",
"sourceIdentifier": "security-advisories@github.com"
}