CVE-2026-79483

FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 21:17

Updated : 2026-09-01 21:00


NVD link : CVE-2026-79483

Mitre link : CVE-2026-79483

CVE.ORG link : CVE-2026-79483


JSON object : View

Products Affected

No product.

CWE
CWE-943

Improper Neutralization of Special Elements in Data Query Logic