Detects FastGPT instances before version 4.14.9.5 where the HTTP tools testing endpoint (/api/core/app/httpTools/runTool) accepts requests without authentication. This endpoint acts as a full HTTP proxy — an attacker can supply any URL and the server will fetch it, enabling access to cloud metadata endpoints, internal services, and private network resources. The fix in 4.14.9.5 adds authCert token validation to gate the endpoint.
Is your app exploitable through CVE-2026-34162?
Scan your domain free