← Volver al buscador de CVEs

CVE-2026-55418

FastGPT

Descripción

FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to the caller-s team. Because S3 object keys are global within the bucket and carry the tenant id only as a path segment, an attacker can supply another team-s key and obtain its file contents through the chat-file presign endpoint or dataset preview endpoint. This issue is fixed in version v4.15.0-beta5.

CVSS 8.6EPSS 0.299%Riesgo 0.88
Ver fuente
Publicación
2026-07-07 22:16:53
Versiones afectadas
<4.15.0-beta5
Tipo
Software crítico
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N