VYPR
Unrated severityNVD Advisory· Published Feb 12, 2026· Updated Feb 13, 2026

Cross-Site Request Forgery (CSRF) in FastGPT

CVE-2026-26075

Description

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization has added stricter internal network address detection. This vulnerability is fixed in 4.14.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Labring/Fastgptllm-fuzzy2 versions
    <4.14.7+ 1 more
    • (no CPE)range: <4.14.7
    • (no CPE)range: < 4.14.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.