Ghostwire / Intelligence Feed / Coverage

CVE-2026-40100 - FastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP default

CVE Feed cybersecurity · April 10, 2026 · Original source
CVE ID :CVE-2026-40100 Published : April 10, 2026, 5:17 p.m. | 49 minutes ago Description :FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool en...

Related Vulnerabilities

Related Coverage

Threat Actors