CVE-2026-40100 | labring FastGPT up to 4.14.10.3 Endpoint runTool isInternalAddress server-side request forgery (GHSA-jrhc-f3j7-f8g4)
A vulnerability was found in labring FastGPT up to 4.14.10.3. It has been declared as critical. The impacted element is the function isInternalAddress of the file /api/core/app/mcpTools/runTool of the component Endpoint. The manipulation results in server-side request forgery.
This vulnerability is known as CVE-2026-40100. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.