PT-2026-56260 · Fastgpt · Fastgpt

CVE-2026-54602

·

Published

2026-07-07

·

Updated

2026-07-08

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FastGPT versions prior to 4.15.0
Description An issue exists where the endpoint "/api/core/ai/record/getRecord" authenticates the caller but fails to implement team scoping when loading LLM request and response traces. By providing a known requestId, any authenticated user can access prompts, retrieved RAG (Retrieval-Augmented Generation) chunks, and completions belonging to other teams.
Recommendations Update to version 4.15.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54602
GHSA-6VX6-F72R-74CG

Affected Products

Fastgpt