Description
FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.
Problem types
CWE-918: Server-Side Request Forgery (SSRF)
Product status
References
github.com/...astGPT/security/advisories/GHSA-573g-3567-8phg