FastGPT, an AI agent building platform, was disclosed with multiple high-severity vulnerabilities affecting both its application and development pipeline. CVE-2026-33075 impacts versions 4.14.8.3 and earlier and stems from the fastgpt-preview-image.yml GitHub Actions workflow using pull_request_target while checking out untrusted fork code. The flaw allows external contributors to achieve arbitrary code execution in GitHub Actions, exfiltrate secrets, and potentially trigger a supply-chain compromise by building and pushing attacker-controlled container images to the production registry. At disclosure, no patch was available for that issue; GitHub tracked it as GHSA-xfx8-w35j-485c.
Two additional flaws, CVE-2026-40351 and CVE-2026-40352, affect FastGPT versions prior to 4.14.9.5 and were fixed in that release. Both are NoSQL injection bugs caused by missing runtime validation in password-handling logic. The first lets an unauthenticated attacker bypass login checks by supplying MongoDB operators such as a password object matching any value, enabling login as arbitrary users including the root administrator. The second lets an authenticated low-privileged user bypass old-password verification in the password-change endpoint, enabling unauthorized password resets and possible account takeover, with broader impact if combined with ID manipulation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
GitHub security advisories published details for CVE-2026-40351 and CVE-2026-40352, describing NoSQL injection flaws in FastGPT versions prior to 4.14.9.5. The disclosures said the bugs could allow login as any user, including root, and unauthorized password changes leading to account takeover.
FastGPT released version 4.14.9.5 to fix two NoSQL injection vulnerabilities: CVE-2026-40351 in loginByPassword, which could let an unauthenticated attacker bypass authentication, and CVE-2026-40352 in updatePasswordByOld, which could let an authenticated attacker bypass old-password checks and take over accounts.
A security advisory disclosed CVE-2026-33075 affecting FastGPT 4.14.8.3 and earlier, caused by a GitHub Actions workflow using pull_request_target while checking out untrusted fork code. The flaw could enable arbitrary code execution, secret exfiltration, and potential supply-chain compromise through attacker-controlled container builds, and no patch was available at disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.