CVE-2026-40351
CRITICALFastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass
Title source: cnaDescription
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. This issue has been fixed in version 4.14.9.5.
References (3)
Scores
CVSS v3
9.8
EPSS
0.0006
EPSS Percentile
18.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-943
Status
published
Products (1)
labring/FastGPT
< 4.14.9.5
Published
Apr 17, 2026
Tracked Since
Apr 18, 2026