FastGPT AI agent platform: unauthenticated SSRF and cross-tenant access control flaws
Two vulnerabilities were disclosed in the FastGPT AI agent building platform: an unauthenticated SSRF via the /api/core/app/mcpTools/runTool endpoint (CVE-2026-40100, fixed in 4.14.10.3) and a broken access control (IDOR/BOLA) issue allowing any authenticated team to access and execute other teams' applications (CVE-2026-40252, fixed in 4.14.10.4). Both enable access to resources beyond the attacker's authorisation, including cross-tenant data exposure and execution of private AI workflows.
Disclosed 10 April 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could perform SSRF against internal network resources, and authenticated teams could access and execute other teams' private AI applications, causing cross-tenant data exposure.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40100
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40252
