Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

FastGPT AI agent platform: unauthenticated plugin API access and SSRF flaws

Two vulnerabilities were disclosed in FastGPT, an AI agent building platform: versions 4.14.0-4.14.5 allowed unauthenticated access to the plugin system via /api/plugin/xxx, potentially crashing it and losing plugin installation state, and server-side fetching nodes (web page acquisition, HTTP nodes) allowed requests to internal network addresses. Fixes shipped in 4.14.5-fix and 4.14.7 respectively.

Disclosed 10 February 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers could reach the plugin system, potentially causing it to crash and lose plugin installation status (no key leakage reported); server-side request nodes could be pointed at internal network addresses.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26003
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26075