Junglewise Threat Intelligence

CVE-2026-54602: labring FastGPT IDOR in AI record retrieval API

CVE-2026-54602 · Severity: info · CVSS 7.1 · Published 2026-07-07

Executive brief

FastGPT, an AI application platform, contains a security flaw that allows users to view sensitive data belonging to other teams. By using a specific request identifier, an authenticated user can access private chat prompts, AI-generated responses, and internal data chunks retrieved from other organizations' knowledge bases. This could lead to the exposure of proprietary business information or private user interactions.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the 'GET /api/core/ai/record/getRecord' endpoint of FastGPT. While the endpoint authenticates the caller, it fails to implement proper multi-tenant scoping (team-based authorization). The underlying database schema for 'llm_request_records' lacks a 'teamId' field, and the controller retrieves records using only the 'requestId'. Consequently, any authenticated user who knows or guesses a 'requestId' can retrieve the full LLM request and response traces of another team, including prompts and RAG (Retrieval-Augmented Generation) chunks. The issue is resolved in version 4.15.0 by adding team-based constraints to the record lookup.

Affected products

  • labring FastGPT < 4.15.0

Timeline

  • 2026-06-25: patched: Fix committed to repository
  • 2026-07-01: advisory: GitHub security advisory published
  • 2026-07-07: disclosed: NVD publication date

References