CVE-2026-40100
Medium Severity
Description
FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The in...
Related Vulnerabilities
- CVE-2026-6027: A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the func CRITICAL
- CVE-2026-6042: A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the MEDIUM
- CVE-2026-22560: An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected MEDIUM
- CVE-2026-40194: phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_ LOW
- CVE-2026-6011: A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown f MEDIUM
Related Coverage
Threat Actors