Back to Database
Status published
Medium
CVE-2025-62612
FastGPT File Reading Node SSRF Vulnerability
Vulnerability Description
FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62612
Credits & Attribution
No credits recorded in the NVD database.
More from labring
View All →CVE-2025-52552
FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSS
Medium
5.5
CVE-2025-49131
FastGPT Sandbox Vulnerable to Sandbox Bypass
Medium
6.3
CVE-2025-27600
FastGPT SSRF
Medium
6.9
CVE-2023-50253
laf logs leak
Critical
9.7
CVE-2023-48225
Laf env causes sensitive information disclosure
High
8.9
Affected Vendor
labring
View all reports →Affected Software
FastGPT
Vulnerable Versions:
< 4.11.1
Timeline
Official Publish:
October 22nd, 2025
Last Modified:
October 23rd, 2025
Added to House:
July 22nd, 2026