Junglewise Threat Intelligence

CVE-2026-40100: labring FastGPT SSRF in mcpTools runTool endpoint

CVE-2026-40100 · Severity: medium · CVSS 5.3 · Published 2026-04-10

Technologies: Fastgpt. Vendors: Fastgpt.

Executive brief

FastGPT, an AI agent building platform, contains a security flaw that allows unauthorized individuals to probe internal network resources. By sending specially crafted requests to a specific tool-running component, an attacker can bypass security checks and access private internal services that are not intended to be public. This could lead to the exposure of sensitive internal data or information about the organization's private infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in FastGPT's /api/core/app/mcpTools/runTool endpoint. The root cause is twofold: the endpoint lacks authentication middleware, and the internal IP validation function (isInternalAddress) is disabled by default, only blocking private IPs if the CHECK_INTERNAL_IP environment variable is explicitly set to 'true'. An unauthenticated remote attacker can provide an arbitrary URL in the 'url' parameter, causing the server to make requests to internal network resources. This can be used to scan internal ports or access internal services. The vulnerability is addressed in version 4.14.10.3.

Affected products

  • labring FastGPT < 4.14.10.3

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: advisory
  • 2026-04-10: patched

References

Related threats