Junglewise Threat Intelligence

CVE-2026-42343: labring FastGPT resource exhaustion in code-sandbox

CVE-2026-42343 · Severity: info · CVSS 6.3 · Published 2026-05-08

Executive brief

FastGPT is an AI platform used to build and deploy intelligent agents. A flaw in its code execution sandbox allows attackers to overwhelm the system by consuming excessive memory or CPU resources. This can lead to a complete service outage, preventing legitimate users from using the platform and potentially increasing infrastructure costs.

Technical details

The code-sandbox component in FastGPT (versions <= 4.14.13) fails to implement strict OS-level resource constraints like cgroups or kernel-level namespaces. Instead, it relies on an application-level soft limit that polls memory usage every 500ms. This creates a timing window where an attacker can allocate and release large amounts of memory between checks to evade detection. Additionally, attackers can exhaust the JavaScript worker pool by submitting concurrent CPU-intensive requests or infinite loops, resulting in a Denial of Service (DoS) for the sandbox service. As of publication, no patches are available.

Affected products

  • labring FastGPT <= 4.14.13

Timeline

  • 2026-04-28: advisory: GitHub Security Advisory published
  • 2026-05-08: disclosed: CVE-2026-42343 published to NVD

References