CVE-2026-40100
Medium Severity
Description
FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The in...
Related Vulnerabilities
- CVE-2026-6004: A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown MEDIUM
- CVE-2026-5466: wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the sig HIGH
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-35662: OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing le MEDIUM
- CVE-2026-4305: The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
Related Coverage
Threat Actors