FastGPT SSRF flaws in HTTP and MCP tools endpoints (CVE-2026-34162/34163)
FastGPT versions before 4.14.9.5 exposed an unauthenticated HTTP tools testing endpoint that acted as a full server-side HTTP proxy, and MCP tools endpoints that made server-side requests to user-supplied URLs without internal-address validation, enabling SSRF against internal networks, cloud metadata services, MongoDB and Redis. Both issues were patched in version 4.14.9.5.
Disclosed 31 March 2026 · Record updated 13 September 2026
Impact
Attackers could proxy arbitrary HTTP requests through the server without authentication, and authenticated attackers could scan internal networks, reach cloud metadata services and internal services such as MongoDB and Redis.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34162
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34163
