Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

FastGPT NoSQL injection flaws allow authentication bypass and account takeover

FastGPT, an AI agent building platform, contained two NoSQL injection vulnerabilities (CVE-2026-40351 and CVE-2026-40352) in versions before 4.14.9.5. The login endpoint accepted MongoDB query operators as a password, letting unauthenticated attackers log in as any user including the root administrator, while the password change endpoint allowed bypassing old-password verification for full account takeover and persistence. Both were fixed in version 4.14.9.5.

Disclosed 17 April 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers could log in as any user, including the root administrator, and authenticated attackers could change passwords without knowing the current one, enabling full account takeover and persistence on affected FastGPT instances.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40351
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40352