Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

FastGPT SSRF and code sandbox escape flaws fixed in 4.15.0-beta1

Two vulnerabilities were disclosed in the FastGPT AI agent building platform: an SSRF in the dataset preview endpoint that bypasses internal-address protection to reach internal services, and a JavaScript sandbox filter bypass (import/**/(...)) allowing arbitrary command execution inside the sandbox container. Both are fixed in version 4.15.0-beta1.

Disclosed 29 May 2026 · Record updated 13 September 2026

Impact

An authenticated attacker could make arbitrary HTTP GET requests to internal network services, and could execute arbitrary commands as the sandbox user inside the code-sandbox container.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44285
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44287