Executive brief
FastGPT is an AI platform used to build and deploy automated agents. A security flaw in its JavaScript execution environment allows users to bypass safety restrictions and run unauthorized commands on the underlying server. This could lead to a complete compromise of the sandbox container, potentially allowing an attacker to disrupt operations or access internal system resources.
Technical details
A sandbox escape vulnerability exists in the FastGPT JavaScript sandbox worker (`projects/code-sandbox/src/pool/worker.ts`). The application attempts to prevent unauthorized module loading by using a regular expression `/\bimport\s*\(/` to block dynamic `import()` calls. However, this regex only accounts for standard whitespace and fails to detect JavaScript block comments (e.g., `/**/`) placed between the `import` keyword and the parenthesis. An attacker can use a payload like `import/**/("child_process")` to bypass the check. Because the `safeRequire` Proxy only wraps `require()` and not `import()`, the attacker can load the `child_process` module and execute arbitrary system commands via `execSync`. This is exploitable by any user with permissions to author workflows or via unauthenticated API access if `SANDBOX_TOKEN` is not configured. The issue is fixed in version 4.15.0-beta1.
Affected products
- labring FastGPT < 4.15.0-beta1
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: CVE published to NVD
- 2026-05-29: patched: Fix released in version 4.15.0-beta1