MEDIUMVulnerability

CVE-2026-79483

FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.

Properties

severity
MEDIUM
score
5.3
epss_score
0.00369
cve_id
CVE-2026-79483
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
published_at
2026-08-31T21:17:49.120
last_modified
2026-09-01T21:00:36.830
epss_percentile
0.30029

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements in Data Query Logic

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-79483 — Ninja Signal Threat Intelligence | Ninja Signal