Hard-coded CredentialsWeakness · CWE-798

CVE-2026-61684

HIGH · 8.8 CVSS v4.0 Published 2026-07-15
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
97/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click 5 weeks old

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official deployment templates. An unauthenticated attacker can self-sign an HS256 JWT and reach /api/invoke/userInfo to disclose cross-tenant user PII by attacker-supplied tmbId values, or /api/invoke/fileUpload to write attacker-controlled content into chat files. This issue is fixed in version 4.15.0-beta5.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

FastGPT versions 4.15.0-beta4 use a hardcoded default JWT secret ('token') for authentication on plugin reverse-call endpoints under /api/invoke/*. Attackers can self-sign HS256 tokens with this known secret to bypass authentication, enabling unauthorized access to cross-tenant user PII via /api/invoke/userInfo and arbitrary file uploads via /api/invoke/fileUpload.

MitigationImmediately upgrade to FastGPT 4.15.0-beta5 or later, and rotate the INVOKE_TOKEN_SECRET to a strong, unique value in all deployments.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
Authentication
X
User interaction
None
Scope
X

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify FastGPT version
    Check the installed FastGPT version by reviewing the deployment configuration, Docker image tag, or the application startup logs. Look for version identifiers in the docker-compose.yml, Helm values, or the running container's labels.
    Affected if The installed version is exactly 4.15.0-beta4 or any version prior to 4.15.0-beta5.
  2. Locate INVOKE_TOKEN_SECRET configuration
    Search for the INVOKE_TOKEN_SECRET environment variable or configuration setting in your FastGPT deployment files, including docker-compose.yml, .env files, Kubernetes secrets, or configuration maps.
    Affected if The INVOKE_TOKEN_SECRET is either not defined, commented out, or explicitly set to the value 'token'.
  3. Verify API endpoint exposure
    Confirm whether the /api/invoke/* endpoints are exposed to network traffic. Check your reverse proxy, firewall rules, or network policies to determine if these endpoints are reachable from untrusted networks.
    Affected if The /api/invoke/userInfo or /api/invoke/fileUpload endpoints are accessible from the network without additional authentication layers.
  4. Confirm JWT validation is in use
    Review the FastGPT configuration to verify that the invoke functionality is enabled and uses INVOKE_TOKEN_SECRET for JWT validation. Check if the invoke feature flag is turned on in the deployment.
    Affected if The invoke feature is enabled and relies solely on INVOKE_TOKEN_SECRET for authentication without additional verification layers.

You are affected if FastGPT version is 4.15.0-beta4, the INVOKE_TOKEN_SECRET is set to the hardcoded default 'token', and the /api/invoke endpoints are exposed to network traffic.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Immediately upgrade to FastGPT 4.15.0-beta5 or later, and rotate the INVOKE_TOKEN_SECRET to a strong, unique value in all deployments.

Recommended fix High confidence

4.15.0-beta5 or later

  1. Upgrade FastGPT from version 4.15.0-beta4 to version 4.15.0-beta5 or later
  2. After upgrading, ensure the INVOKE_TOKEN_SECRET environment variable is set to a strong, unique secret value in production deployments
  3. Restart all FastGPT services to apply the new configuration

Generated from the published advisory — verify against the referenced sources before acting.

Have this fixed Scoped from the published advisory
  • Consultation4.0 h
  • Implementation2.0 h
  • Testing4.0 h
  • Review / QA2.0 h
12.0 hours of engineering $2,120
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,392.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-61684 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-61684 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data