Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Multiple vulnerabilities disclosed in FastGPT AI agent platform, including sandbox RCE

Six CVEs were published for FastGPT, an AI agent building platform, covering unauthenticated remote code execution in the agent-sandbox (code-server started with --auth none bound to 0.0.0.0:8080), several SSRF/DNS-rebinding and cloud metadata blocklist bypasses, and uncontrolled resource consumption in the code-sandbox leading to denial of service. Some issues were fixed in versions 4.14.13 and 4.14.17, while others had no public patch at publication.

Disclosed 8 May 2026 · Record updated 13 September 2026

Impact

Attackers with network access could gain full control of the sandbox environment via unauthenticated RCE, force the backend to make requests to internal/private addresses and cloud metadata endpoints via SSRF, or exhaust the JavaScript worker pool to deny service to legitimate users.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42302
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42343
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42344
  4. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42345
  5. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44284
  6. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44286