FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes guardrails intended to prevent file writes (static detection + seccomp). These guardrails are bypassable by remapping stdout (fd 1) to an arbitrary writable file descriptor using fcntl. After remapping, writing via sys.stdout.write() still satisfies the seccomp rule write(fd==1), enabling arbitrary file creation/overwrite inside the sandbox container despite the intended no file writes restriction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python audit/exploit tool for FastGPT's Python sandbox, not a framework module. It contains one executable script (fastgpt-sandbox-audit.py), a README, and a minimal .gitignore. The script supports four modes: --check for static analysis of a local worker.py sandbox implementation, --exploit for local sandbox escape validation via the worker's stdin JSON protocol, --dump for environment-variable enumeration, and --http for submitting the escape payload to a remote FastGPT sandbox API. The core exploit capability is a Python sandbox escape based on importing inspect, accessing inspect.currentframe().f_back.f_globals, and retrieving leaked privileged references such as _original_open and _original_import from the worker module's global scope. Using these references, the tool bypasses Python-layer blacklist and AST protections to read arbitrary files (/etc/passwd as proof), write files (/tmp/pwned_by_audit.txt), and import os to inspect environment variables. In HTTP mode it targets POST /sandbox/python and assumes the endpoint may be unauthenticated. Repository structure is simple: the README documents affected FastGPT versions and usage, while the Python script implements both detection and exploitation logic. The code does not deliver a shell or persistence; instead it demonstrates practical post-bypass capabilities inside the sandbox/container context. Because it includes working payloads with hardcoded actions and supports both local and remote submission paths, it is best classified as an operational exploit/audit utility rather than a mere detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.