CVE Explorer
CVE-2026-40352
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without knowing the current one, leading to full account takeover and persistence. This issue has been fixed
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"FastGPT","vendor":"labring","versions":[{"status":"affected","version":"< 4.14.9.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ba4b422432a5db4c326a2c9cf750835e64cf96806993ce458b828b3b575f7871 · sha256:18c54474823c05f2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ba4b422432a5db4c326a2c9cf750835e64cf96806993ce458b828b3b575f7871 · sha256:18c54474823c05f2… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-943","description":"CWE-943: Improper Neutralization of Special Elements in Data Query Logic","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ba4b422432a5db4c326a2c9cf750835e64cf96806993ce458b828b3b575f7871 · sha256:18c54474823c05f2… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d","tags":["x_refsource_MISC"],"url":"https://github.com/labring/FastGPT/commit/bd966d479fbe414d02679cf79f9eaaab3d100a2d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ba4b422432a5db4c326a2c9cf750835e64cf96806993ce458b828b3b575f7871 · sha256:18c54474823c05f2… · /containers/cna/references/1
{"name":"https://github.com/labring/FastGPT/releases/tag/v4.14.9.5","tags":["x_refsource_MISC"],"url":"https://github.com/labring/FastGPT/releases/tag/v4.14.9.5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ba4b422432a5db4c326a2c9cf750835e64cf96806993ce458b828b3b575f7871 · sha256:18c54474823c05f2… · /containers/cna/references/2
{"name":"https://github.com/labring/FastGPT/security/advisories/GHSA-422w-vrfj-72g6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/labring/FastGPT/security/advisories/GHSA-422w-vrfj-72g6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ba4b422432a5db4c326a2c9cf750835e64cf96806993ce458b828b3b575f7871 · sha256:18c54474823c05f2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.