Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18916 | FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9.12. |
Mon, 29 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastgpt
Fastgpt fastgpt |
|
| CPEs | cpe:2.3:a:fastgpt:fastgpt:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fastgpt
Fastgpt fastgpt |
|
| Metrics |
cvssV3_1
|
Mon, 23 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 21 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controlled sites. This issue has been patched in version 4.9.12. | |
| Title | FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSS | |
| Weaknesses | CWE-601 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-23T17:42:33.181Z
Reserved: 2025-06-18T03:55:52.034Z
Link: CVE-2025-52552
Updated: 2025-06-23T17:42:28.916Z
Status : Analyzed
Published: 2025-06-21T03:15:24.990
Modified: 2025-12-29T19:06:40.077
Link: CVE-2025-52552
No data.
OpenCVE Enrichment
No data.
EUVD