Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

AstrBotDevs — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting AstrBotDevs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AstrBotDevs develops an AI chatbot management platform primarily used for automating customer interactions and support services. Historically, their software has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and authentication flaws. The project maintains six CVE records, with several critical issues allowing unauthorized system access and data exfiltration. While no major public security incidents have been documented, the consistent pattern of vulnerabilities in web interfaces and API endpoints suggests ongoing challenges in secure coding practices, particularly in handling user-supplied data and access control mechanisms.

Found 21 results / 21 Clear Filters
Top products by AstrBotDevs: AstrBot
CVE ID Title CVSS Severity Published
CVE-2026-17530 AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization — AstrBot CWE-863 6.3 Medium 2026-07-27
CVE-2026-17529 AstrBotDevs AstrBot astr_main_agent.py authorization — AstrBot CWE-863 6.3 Medium 2026-07-27
CVE-2026-16077 AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following — AstrBot CWE-59 5.3 Medium 2026-07-18
CVE-2026-16076 AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing — AstrBot CWE-290 6.3 Medium 2026-07-18
CVE-2026-16075 AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization — AstrBot CWE-639 4.3 Medium 2026-07-18
CVE-2026-16074 AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery — AstrBot CWE-918 6.3 Medium 2026-07-17
CVE-2026-16073 AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting — AstrBot CWE-79 3.5 Low 2026-07-17
CVE-2026-15501 AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery — AstrBot CWE-918 6.3 Medium 2026-07-12
CVE-2026-15500 AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery — AstrBot CWE-918 6.3 Medium 2026-07-12
CVE-2026-15499 AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization — AstrBot CWE-285 6.3 Medium 2026-07-12
CVE-2026-10213 AstrBotDevs AstrBot API Endpoint delete path traversal — AstrBot CWE-22 5.4 Medium 2026-06-01
CVE-2026-10212 AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization — AstrBot CWE-639 6.3 Medium 2026-06-01
CVE-2026-10211 AstrBotDevs AstrBot fs.py _normalize_rw_path authorization — AstrBot CWE-863 6.3 Medium 2026-06-01
CVE-2026-10210 AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection — AstrBot CWE-74 6.3 Medium 2026-06-01
CVE-2026-8754 AstrBotDevs AstrBot File Upload chat.py post_file path traversal — AstrBot CWE-22 6.3 Medium 2026-05-17
CVE-2026-7579 AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials — AstrBot CWE-798 7.3 High 2026-05-01
CVE-2026-6984 AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine — AstrBot CWE-1336 4.7 Medium 2026-04-25
CVE-2026-6119 AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery — AstrBot CWE-918 6.3 Medium 2026-04-12
CVE-2026-6118 AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection — AstrBot CWE-77 6.3 Medium 2026-04-12
CVE-2026-6117 AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox — AstrBot CWE-265 6.3 Medium 2026-04-12
CVE-2025-48957 AstrBot Has Path Traversal Vulnerability in /api/chat/get_file — AstrBot CWE-23 7.5 High 2025-06-02

This page lists every published CVE security advisory associated with AstrBotDevs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.