SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79483

MEDIUM · CVSS 5.3 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

FastGPT Community Edition versions 4.10.0 to 4.14.0 are susceptible to a NoSQL injection vulnerability in the POST /api/core/chat/getHistories endpoint, allowing unauthenticated attackers to exploit crafted JSON payloads. This flaw enables attackers to bypass authorization checks and gain unauthorized access to the chat history titles of all users. Organizations using these versions should prioritize remediation to protect user data and maintain platform integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79483
Severity
MEDIUM
CVSS
5.3
EPSS
0.37%

Original NVD Description

FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.