CVE-2026-79483

Source
https://cve.org/CVERecord?id=CVE-2026-79483
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79483.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79483
Published
2026-08-31T00:00:00Z
Modified
2026-09-02T03:47:30.133474940Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79483.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/labring/fastgpt

Affected ranges

Type
GIT
Repo
https://github.com/labring/fastgpt
Events
Database specific
Show details
{
    "source": "DESCRIPTION",
    "extracted_events": [
        {
            "introduced": "4.10.0"
        },
        {
            "fixed": "4.14.0"
        }
    ]
}

Affected versions

v4.*
v4.10.0-fix
v4.10.1
v4.10.1-alpha
v4.10.1-fix
v4.10.1-fix2
v4.10.1-fix3
v4.11.0
v4.11.1
v4.11.1-fix
v4.11.1-fix2
v4.11.1-fix3
v4.12.0
v4.12.1
v4.12.1-fix
v4.12.2
v4.12.2-fix
v4.12.2-fix2
v4.12.2-fix3
v4.12.3
v4.12.4
v4.13.0
v4.13.0-fix
v4.13.1
v4.13.2
v4.14.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79483.json"