AstrBot老版本RCE# 介绍
AstrBot<=3.5.17在[源码中](https://github.com/AstrBotDevs/AstrBot/blob/v3.5.17/astrbot/core/__init__.py)硬编码了JWT secret,导致可以任意上传插件,实现RCE
# 使用
```shell
python main.py 'http://127.0.0.1:6185'
```
# 源码
https://github.com/AstrBotDevs/AstrBot.git
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view