Archer
6 exploits
Active since Jun 2025
FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass
CVSS 9.8
FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover
CVSS 8.8
FastGPT: Unauthenticated SSRF via httpTools Endpoint Leads to Internal API Key Theft
CVSS 10.0
Server-Side Request Forgery via MCP Tools Endpoint in FastGPT
CVSS 7.7
Fastgpt < 4.9.12 - XSS
CVSS 6.1
FastGPT <4.14.5 - Unauthenticated RCE
CVSS 5.4