Descrição
FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unrelated resource and then sign or read an S3 object using a key taken directly from the request, without checking that the key belongs to the caller-s team. Because S3 object keys are global within the bucket and carry the tenant id only as a path segment, an attacker can supply another team-s key and obtain its file contents through the chat-file presign endpoint or dataset preview endpoint. This issue is fixed in version v4.15.0-beta5.
CVSS 8.6EPSS 0.299%Risco 0.88
Ver fonte- Publicação
- 2026-07-07 22:16:53
- Versões afetadas
- <4.15.0-beta5
- Tipo
- Software crítico
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N