Junglewise Threat Intelligence

CVE-2026-42344: Labring FastGPT DNS rebinding SSRF in isInternalAddress

CVE-2026-42344 · Severity: medium · CVSS 6.3 · Published 2026-05-08

Executive brief

FastGPT is an AI agent building platform that allows users to create and deploy AI-driven tools. A security flaw in how the system validates web addresses allows an attacker to bypass internal security filters. By tricking the system into connecting to restricted internal servers or cloud metadata services, an attacker could steal sensitive credentials or access private company data that is not intended to be public.

Technical details

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in FastGPT's isInternalAddress() function. The application performs a DNS resolution to validate that a target IP is not within a private range, but then performs a second, independent DNS resolution when executing the actual HTTP request via axios or fetch. An attacker can use a DNS rebinding server to return a public IP during the validation phase and a private/internal IP (such as 169.254.169.254) during the fetch phase. This bypasses SSRF protections across multiple endpoints, including HTTP tool schema fetching and MCP tool execution. As of the advisory date, no patches are available; remediation requires DNS pinning to ensure the validated IP is the same one used for the connection.

Affected products

  • labring FastGPT <= 4.14.11

Timeline

  • 2026-04-21: other: Vulnerability confirmed on version 4.14.11 (commit e6584ac)
  • 2026-04-28: advisory: GitHub Security Advisory published
  • 2026-05-08: disclosed: CVE-2026-42344 published to NVD

References