Vulnerability Description
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/ExploreIO/CVE-2026-79483-FastGPT-NoSQL-Injection
- https://github.com/labring/FastGPT
- https://github.com/ExploreIO/CVE-2026-79483-FastGPT-NoSQL-Injection
FAQ
What is CVE-2026-79483?
CVE-2026-79483 is a vulnerability with a CVSS score of 5.3 (MEDIUM). FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators v...
How severe is CVE-2026-79483?
CVE-2026-79483 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-79483?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.