在 AstrBotDevs 的 AstrBot(版本低于或等于 4.25.5)中发现了一个安全漏洞。受此漏洞影响的组件是 Subagent,具体涉及文件 AstrBot/astrbot/core/astr_agent_tool_exec.py 中的 _build_handoff_toolset 函数。该漏洞可导致授权逻辑错误,攻击者可能通过远程方式发起攻击。目前该漏洞的利用代码已公开,可能被用于实际攻击。修复补丁的版本标识为 d23011262e8e75e1ec41b0f1f0091493a022327e。建议尽快
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AstrBotDevs | AstrBot | 4.25.0 |
affected |
4.25.1 |
affected | ||
4.25.2 |
affected | ||
4.25.3 |
affected | ||
4.25.4 |
affected | ||
4.25.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AstrBotDevs | AstrBot | 4.25.0 |
cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet