Junglewise Threat Intelligence

CVE-2026-44285: labring FastGPT SSRF in dataset preview API

CVE-2026-44285 · Severity: high · CVSS 7.7 · Published 2026-05-29

Executive brief

FastGPT is an AI platform used to build and manage AI agents. A security flaw allows logged-in users to bypass network protections and force the server to access internal company resources or cloud metadata. This could lead to the theft of sensitive internal data, such as private documents or cloud service credentials, which are normally hidden from the public internet.

Technical details

A Server-Side Request Forgery (SSRF) exists in FastGPT due to an incomplete fix in the dataset preview functionality. Specifically, the '/api/core/dataset/file/getPreviewChunks' endpoint fails to apply 'isInternalAddress' validation when the 'externalFile' data import type is used. An authenticated attacker can provide a malicious URL via the 'sourceId' parameter, which is then processed by the 'readFileRawTextByUrl' function using axios without network restrictions. This allows the attacker to perform GET requests against internal IP addresses (e.g., 127.0.0.1, 172.x.x.x) or cloud metadata services (169.254.169.254) and receive the reflected content in the application's response. The issue is resolved in version 4.15.0-beta1.

Affected products

  • labring FastGPT < 4.15.0-beta1

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References