Unrated severityNVD Advisory· Published Feb 12, 2026· Updated Feb 13, 2026
Cross-Site Request Forgery (CSRF) in FastGPT
CVE-2026-26075
Description
FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization has added stricter internal network address detection. This vulnerability is fixed in 4.14.7.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/labring/FastGPT/releases/tag/v4.14.7mitrex_refsource_MISC
- github.com/labring/FastGPT/security/advisories/GHSA-g345-7pqp-c395mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.