We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9.12.
Reserved 2025-06-18 | Published 2025-06-21 | Updated 2025-06-21 | Assigner GitHub_MCWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
github.com/...astGPT/security/advisories/GHSA-r976-rfrv-q24m
github.com/...ommit/095b75ee27746004106eddeaa4840688a61ff6eb
Support options