{"id":"CVE-2026-61684","summary":"FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')","details":"FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official deployment templates. An unauthenticated attacker can self-sign an HS256 JWT and reach /api/invoke/userInfo to disclose cross-tenant user PII by attacker-supplied tmbId values, or /api/invoke/fileUpload to write attacker-controlled content into chat files. This issue is fixed in version 4.15.0-beta5.","aliases":["GHSA-w732-rq8c-chc8"],"modified":"2026-07-17T03:48:22.556068146Z","published":"2026-07-15T14:28:22.480Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-798"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61684.json"},"references":[{"type":"WEB","url":"https://github.com/labring/FastGPT/releases/tag/v4.15.0-beta5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61684.json"},{"type":"ADVISORY","url":"https://github.com/labring/FastGPT/security/advisories/GHSA-w732-rq8c-chc8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61684"},{"type":"FIX","url":"https://github.com/labring/FastGPT/commit/f5f1e58b25571b7107ca49d9bf96bb2b0e0a620a"},{"type":"FIX","url":"https://github.com/labring/FastGPT/pull/7170"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/labring/fastgpt","events":[{"introduced":"8784b62215721c87e7bd2f35d45a4e29e07d38f5"},{"fixed":"f5f1e58b25571b7107ca49d9bf96bb2b0e0a620a"},{"fixed":"0c1840c7773c5be5d777f86228651479e02155db"}],"database_specific":{"extracted_events":[{"introduced":"= 4.15.0-beta4"},{"last_affected":"= 4.15.0-beta4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["= 4.15.0-beta4","v4.15.0-beta4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61684.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}