CVE-2026-54602
Last modified
CVE-2026-54602 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without team scoping, allowing any authenticated user to read another team's prompts, retrieved RAG chunks, and completions if the requestId is known. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates the caller but loads LLM request and response traces only by requestId without team scoping, allowing any authenticated user to read another team's prompts, retrieved RAG chunks, and completions if the requestId is known. This issue is fixed in version 4.15.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| labring | FastGPT | < 4.15.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54602?
How severe is CVE-2026-54602?
How do I fix CVE-2026-54602?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54597ITFlow provides an IT documentation, ticketing and accountin…8.3
- CVE-2026-54598Wallos is an open-source, self-hostable personal subscriptio…7.5
- CVE-2026-54599Wallos is an open-source, self-hostable personal subscriptio…7.5
- CVE-2026-5460A heap use-after-free exists in wolfSSL's TLS 1.3 post-quant…6.5
- CVE-2026-54600Wallos is an open-source, self-hostable personal subscriptio…8.2
- CVE-2026-54601FastGPT is an open source AI knowledge base platform. From 4…6.3
- CVE-2026-54603OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authoriza…8.6
- CVE-2026-54604OpenSlide is a C library for reading whole slide image files…5.3
- CVE-2026-54605OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols…7.2
- CVE-2026-54606SunEditor is a lightweight and powerful WYSIWYG editor in va…8.5
- CVE-2026-54607FastGPT is a knowledge-based AI application platform. Prior …7.7
- CVE-2026-54608MythicalDash is a Pterodactyl client area. In 3.5.4-aurora a…7.1
Are you affected by CVE-2026-54602?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
