FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSS
Vulnerability Description
FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9.12.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52552
Credits & Attribution
No credits recorded in the NVD database.
References
More from labring
View All →Affected Vendor
labring
View all reports →