UNKNOWNCVE-2026-34162

FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft

Platform

nodejs

Component

fastgpt

Fixed in

4.14.9.5

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes a server-side HTTP request and returns the complete response to the caller. This issue has been patched in version 4.14.9.5.

How to fix

Actualice FastGPT a la versión 4.14.9.5 o superior. Esta versión corrige la vulnerabilidad SSRF no autenticada en el endpoint /api/core/app/httpTools/runTool, que permitía el robo de claves API internas.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free
CVE-2026-34162 — Vulnerability Details | NextGuard | NextGuard