Impact
In prior releases of FastGPT, the WeChat (iLink) share‑channel endpoints authorize all requests solely based on the public shareId, omitting any authenticated identity or team‑ownership verification. This flaw allows an unauthenticated attacker who learns a victim team’s shareId—exposed in shared chat URLs, iframes, and embeds—to modify or delete the team’s WeChat binding. By invoking the malformed logout or status endpoints, an attacker can cause the bot to go offline, hijack the channel with their own bot, expose private responses, and exhaust the victim team’s resources. The vulnerability results in unauthorized privileged operations, leading to confidentiality, integrity, and availability compromises. The problem is described by CWE-306 and CWE-862.
Affected Systems
Affected vendor is labring with its FastGPT platform. The flaw exists in all versions prior to 4.15.2, where shareId-based authorization checks were missing. The vulnerability was addressed in release 4.15.2.
Risk and Exploitability
The CVSS score of 9.3 classifies the vulnerability as critical. The EPSS data is not available, but the lack of authentication coupled with the public nature of the shareId makes exploitation straightforward and the likelihood of discovery high. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. An attacker can leverage the endpoint directly over the internet, without requiring additional credentials, to hijack the channel or mount a denial‑of‑service attack.
OpenCVE Enrichment