Vulnerabilidades em labring

37 resultados
Análise Vexday

A Labring apresenta um panorama preocupante com 35 vulnerabilidades catalogadas, sendo 17 delas publicadas nos últimos 90 dias, o que indica um padrão recente de descobertas de segurança. Embora nenhuma esteja sob exploração ativa no momento, 7 vulnerabilidades críticas (CVSS elevado) foram identificadas, predominantemente relacionadas à injeção de solicitações HTTP lado do servidor (CWE-918), uma fração significativa do inventário de risco. A concentração em uma fraqueza específica e o ritmo acelerado de divulgações recentes sugerem necessidade de avaliação e correção prioritária nesta superfície de ataque.

CVE-2026-44284MEDIUMFastGPT: Stored MCP tool URL SSRF in FastGPT workflow executionEPSS 0.4%CVE-2026-40100MEDIUMFastGPT has Unauthenticated SSRF in /api/core/app/mcpTools/runTool via missing CHECK_INTERNAL_IP defaultEPSS 0.4%CVE-2026-44286LOWFastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address ValidationEPSS 0.4%CVE-2026-54602HIGHFastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecordEPSS 0.4%CVE-2026-61646MEDIUMFastGPT: Shared axios SSRF guard validates only the initial URL before following redirectsEPSS 0.4%CVE-2026-84301MEDIUMFastGPT safe axios SSRF guard still allows DNS rebinding TOCTOU on protected outbound requestsEPSS 0.4%CVE-2026-44285HIGHFastGPT: SSRF Protection Bypass via `externalFile` in Dataset Preview APIEPSS 0.4%CVE-2026-42345HIGHFastGPT: Cloud metadata endpoint SSRF protection bypass via port specification, IPv6 mapping, hex/decimal IP encoding, and trailing dotEPSS 0.4%CVE-2026-33075CRITICALFastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymlEPSS 0.3%CVE-2026-32128MEDIUMFastGPT Python Sandbox Bypass of File-Write RestrictionEPSS 0.3%CVE-2025-27600MEDIUMFastGPT SSRFEPSS 0.3%CVE-2025-52552MEDIUMFastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSSEPSS 0.3%CVE-2026-61643MEDIUMFastGPT: workflow runtime can execute another user's private HTTP toolsetEPSS 0.3%CVE-2025-62612MEDIUMFastGPT File Reading Node SSRF VulnerabilityEPSS 0.2%CVE-2026-42344MEDIUMFastGPT: DNS rebinding TOCTOU bypass in isInternalAddress allows SSRF on all protected endpointsEPSS 0.2%CVE-2026-50562CRITICALFastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflowsEPSS 0.2%CVE-2026-26075MEDIUMCross-Site Request Forgery (CSRF) in FastGPTEPSS 0.1%