Skip to content

文件读取节点 SSRF 漏洞

Moderate
c121914yu published GHSA-573g-3567-8phg Oct 22, 2025

Package

npm fastgpt/service (npm)

Affected versions

<4.11.1

Patched versions

4.11.1

Description

工作流文件读取节点中,对网络链接未进行安全校验,存在 SSRF 攻击风险。

Severity

Moderate

CVE ID

CVE-2025-62612

Weaknesses

No CWEs

Credits