Impact
A Server‑Side Request Forgery flaw exists in the dataset preview API of FastGPT, enabling an authenticated attacker to bypass the global internal‑address protection and issue arbitrary HTTP GET requests to internal network services. The vulnerability stems from an incomplete fix in the /api/core/dataset/file/getPreviewChunks endpoint when the externalFile data import type is used. The flaw can allow the attacker to read or manipulate internal resources, potentially exposing sensitive data or facilitating further attacks.
Affected Systems
All versions of FastGPT prior to 4.15.0‑beta1 are affected; the vendor is LabRing. The issue applies to authenticated users accessing the dataset preview functionality.
Risk and Exploitability
With a CVSS score of 7.7, the vulnerability is deemed high risk. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Attack requires authentication and relies on the dataset preview endpoint, suggesting that authenticated insiders or compromised user accounts could exploit the flaw. The attacker may access internal services, gather information, or pivot to other network resources if the internal network is not adequately isolated.
OpenCVE Enrichment