CVE-2026-40100 - FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default
CVE ID :CVE-2026-40100
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool en...
Related Vulnerabilities
- CVE-2026-5777: This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bri HIGH
- CVE-2026-33784: A Use of Default Password vulnerability in the Juniper Networks
Support Insights (JSI)
Virtual L CRITICAL
- CVE-2026-40242: Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint HIGH
- CVE-2026-25203: Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability
HIGH
- CVE-2026-40086: Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the MEDIUM
Related Coverage
Threat Actors