Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AstrBot — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in AstrBot, with AI-generated Chinese analysis, references, and POCs.

This page catalogs security vulnerabilities associated with the AstrBot product, categorizing them by vulnerability type and classification tags. It aggregates a comprehensive list of disclosed weaknesses affecting this specific software solution, covering reports from initial discovery through to the most recent updates. By consolidating this data, the page allows users to track the vendor's security advisory history, gaining insight into how quickly and effectively threats are addressed over time. Visitors can also analyze the prevalence of specific weakness classes, such as cross-site scripting or injection flaws, to understand the technical landscape and recurring risks inherent to the product's architecture. Additionally, the resource provides a detailed historical record of every known vulnerability, enabling security teams and developers to audit the product’s past performance and prioritize patching efforts based on severity and exploitability. This centralized view helps organizations assess their exposure risk, compare findings against industry benchmarks, and make informed decisions regarding system hardening and update schedules. The information is strictly factual, offering a transparent look at the security posture of AstrBot without promotional language or speculative commentary.

Vendor: AstrBotDevs

CVE IDTitleCVSSSeverityPublished
CVE-2026-17530 AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization CWE-863 6.3 Medium2026-07-27
CVE-2026-17529 AstrBotDevs AstrBot astr_main_agent.py authorization CWE-863 6.3 Medium2026-07-27
CVE-2026-16077 AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following CWE-59 5.3 Medium2026-07-18
CVE-2026-16076 AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing CWE-290 6.3 Medium2026-07-18
CVE-2026-16075 AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization CWE-639 4.3 Medium2026-07-18
CVE-2026-16074 AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery CWE-918 6.3 Medium2026-07-17
CVE-2026-16073 AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting CWE-79 3.5 Low2026-07-17
CVE-2026-15501 AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery CWE-918 6.3 Medium2026-07-12
CVE-2026-15500 AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery CWE-918 6.3 Medium2026-07-12
CVE-2026-15499 AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization CWE-285 6.3 Medium2026-07-12
CVE-2026-10213 AstrBotDevs AstrBot API Endpoint delete path traversal CWE-22 5.4 Medium2026-06-01
CVE-2026-10212 AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization CWE-639 6.3 Medium2026-06-01
CVE-2026-10211 AstrBotDevs AstrBot fs.py _normalize_rw_path authorization CWE-863 6.3 Medium2026-06-01
CVE-2026-10210 AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection CWE-74 6.3 Medium2026-06-01
CVE-2026-8754 AstrBotDevs AstrBot File Upload chat.py post_file path traversal CWE-22 6.3 Medium2026-05-17
CVE-2026-7579 AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials CWE-798 7.3 High2026-05-01
CVE-2026-6984 AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine CWE-1336 4.7 Medium2026-04-25
CVE-2026-6119 AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery CWE-918 6.3 Medium2026-04-12
CVE-2026-6118 AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection CWE-77 6.3 Medium2026-04-12
CVE-2026-6117 AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox CWE-265 6.3 Medium2026-04-12
CVE-2025-48957 AstrBot Has Path Traversal Vulnerability in /api/chat/get_file CWE-23 7.5 High2025-06-02

All 21 known CVE vulnerabilities affecting AstrBot with full Chinese analysis, references, and POCs where available.