CVE-2026-61684EPSS p41.6%
CVE-2026-61684CVE-2026-61684
Description
FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official deployment templates. An unauthenticated attacker can self-sign an HS256 JWT and reach /api/invoke/userInfo to disclose cross-tenant user PII by attacker-supplied tmbId values, or /api/invoke/fileUpload to write attacker-controlled content into chat files. This issue is fixed in version 4.15.0-beta5.
Scoring
| EPSS | 0.51% probability of exploitation · percentile 41.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-15 |