Unrated severityNVD Advisory· Published Aug 31, 2026
CVE-2026-79483
CVE-2026-79483
Description
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 4.10.0 - 4.14.0
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.