Executive brief
FastGPT, an AI agent building platform, contains a security flaw in its Model Context Protocol (MCP) tools. An authorized user can trick the system into making network requests to internal servers that should be private. This could allow an attacker to scan the company's internal network, access sensitive databases like MongoDB or Redis, or steal cloud service credentials, potentially leading to a broader data breach or service disruption.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in FastGPT's MCP tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool). These endpoints accept a user-supplied URL and initiate server-side HTTP/SSE requests via the MCPClient without validating if the target is an internal or private network address. While FastGPT includes an 'isInternalAddress()' validation function, it was not implemented on these specific routes. An authenticated attacker can exploit this to perform internal port scanning, interact with internal services like Redis and MongoDB, or access cloud metadata services (e.g., 169.254.169.254) to retrieve sensitive credentials. The issue is resolved in version 4.14.9.5 by enforcing internal address checks.
Affected products
- labring FastGPT < 4.14.9.5
Timeline
- 2026-03-25: patched: Fix committed and version 4.14.9.5 released.
- 2026-03-26: advisory: Vendor security advisory published.
- 2026-03-31: disclosed: CVE-2026-34163 published to NVD.