CVE-2026-54601

FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in a way that persists a server-owned datasetId value from another tenant. This creates mixed dataset objects and downstream dataset, collection, and training endpoints then make authorization decisions from inconsistent ownership anchors, allowing cross-tenant read, update, and delete access when mixed object ids are known. This issue is fixed in version 4.15.0-beta4.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-07 22:16

Updated : 2026-07-08 15:07


NVD link : CVE-2026-54601

Mitre link : CVE-2026-54601

CVE.ORG link : CVE-2026-54601


JSON object : View

Products Affected

No product.

CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes