Executive brief
FastGPT is an open-source platform for building AI applications with knowledge bases. Prior to version 4.15.2, a timing gap in DNS validation allows an authenticated attacker to bypass security checks that normally prevent connections to private networks. By supplying a malicious URL to HTTP tools or workflows, an attacker can reach internal services like metadata endpoints or databases that should be blocked, potentially exposing sensitive data or allowing further system compromise.
Technical details
The vulnerability is a time-of-check/time-of-use (TOCTOU) DNS rebinding flaw in packages/service/common/api/axios.ts. The safe axios interceptor validates hostnames with isInternalAddress() before the actual HTTP connection, but the connection performs an independent DNS lookup, allowing an attacker-controlled hostname to resolve to a public address during validation and to a loopback, private, link-local, or metadata address during connection. This requires authentication and the ability to supply URLs to HTTP integrations; the fix pins DNS resolution to prevent rebinding.
Affected products
- Labring FastGPT before 4.15.2
Timeline
- 2026-09-22: disclosed
- 2026-07-06: patched: Fix merged in commit 0a38565c9d1f790045636bd9d55f8d2296c938c7