Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AstrBotDevs — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting AstrBotDevs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

AstrBotDevs develops an AI chatbot management platform primarily used for automating customer interactions and support services. Historically, their software has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and authentication flaws. The project maintains six CVE records, with several critical issues allowing unauthorized system access and data exfiltration. While no major public security incidents have been documented, the consistent pattern of vulnerabilities in web interfaces and API endpoints suggests ongoing challenges in secure coding practices, particularly in handling user-supplied data and access control mechanisms.

Top products by AstrBotDevs: AstrBot
CVE IDTitleCVSSSeverityPublished
CVE-2026-17530 AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization — AstrBotCWE-863 6.3 Medium2026-07-27
CVE-2026-17529 AstrBotDevs AstrBot astr_main_agent.py authorization — AstrBotCWE-863 6.3 Medium2026-07-27
CVE-2026-16077 AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following — AstrBotCWE-59 5.3 Medium2026-07-18
CVE-2026-16076 AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing — AstrBotCWE-290 6.3 Medium2026-07-18
CVE-2026-16075 AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization — AstrBotCWE-639 4.3 Medium2026-07-18
CVE-2026-16074 AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery — AstrBotCWE-918 6.3 Medium2026-07-17
CVE-2026-16073 AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting — AstrBotCWE-79 3.5 Low2026-07-17
CVE-2026-15501 AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery — AstrBotCWE-918 6.3 Medium2026-07-12
CVE-2026-15500 AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery — AstrBotCWE-918 6.3 Medium2026-07-12
CVE-2026-15499 AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization — AstrBotCWE-285 6.3 Medium2026-07-12
CVE-2026-10213 AstrBotDevs AstrBot API Endpoint delete path traversal — AstrBotCWE-22 5.4 Medium2026-06-01
CVE-2026-10212 AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization — AstrBotCWE-639 6.3 Medium2026-06-01
CVE-2026-10211 AstrBotDevs AstrBot fs.py _normalize_rw_path authorization — AstrBotCWE-863 6.3 Medium2026-06-01
CVE-2026-10210 AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection — AstrBotCWE-74 6.3 Medium2026-06-01
CVE-2026-8754 AstrBotDevs AstrBot File Upload chat.py post_file path traversal — AstrBotCWE-22 6.3 Medium2026-05-17
CVE-2026-7579 AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials — AstrBotCWE-798 7.3 High2026-05-01
CVE-2026-6984 AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine — AstrBotCWE-1336 4.7 Medium2026-04-25
CVE-2026-6119 AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery — AstrBotCWE-918 6.3 Medium2026-04-12
CVE-2026-6118 AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection — AstrBotCWE-77 6.3 Medium2026-04-12
CVE-2026-6117 AstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandbox — AstrBotCWE-265 6.3 Medium2026-04-12
CVE-2025-48957 AstrBot Has Path Traversal Vulnerability in /api/chat/get_file — AstrBotCWE-23 7.5 High2025-06-02

This page lists every published CVE security advisory associated with AstrBotDevs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.