CVE-2026-61644
HIGHFastGPT >= 4.14.17, < 4.15.0-beta5 - Cross-Tenant Dataset Disclosure
Title source: manualDescription
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId center-node lookup is not bound to that authorized context. A low-privileged tenant user can call the endpoint with valid attacker-owned appId, chatId, chatItemDataId, and collectionId values while supplying another tenant's dataset data id as initialId, causing the response to include foreign dataset quote or full-text content. This issue is fixed in version 4.15.0-beta5.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/labring/FastGPT/security/advisories/GHSA-mmg6-2g54-j896
X_Refsource_Misc x_refsource_misc
https://github.com/labring/FastGPT/pull/7173
X_Refsource_Misc x_refsource_misc
https://github.com/labring/FastGPT/commit/0c1840c7773c5be5d777f86228651479e02155db
X_Refsource_Misc x_refsource_misc
https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5
Scores
CVSS v3
7.7
EPSS
0.0024
EPSS Percentile
15.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (1)
labring/FastGPT
>= 4.14.17, < 4.15.0-beta5
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026