CVE-2025-57697Medium▾ SunlitAstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image_bs64 function defined in entities.py opens the image specified by the user in the request body and returns the image content as a base64-encoded string without checking the legitimacy of the image path, attackers can construct a series of malicious URLs to read any specified file, resulting in sensitive data leakage.
astrbot <= 3.5.22Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6984Medium· 4.7AstrBot has Incomplete Filtering of Special Elements
CVE-2026-8754Medium· 6.3AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability
CVE-2026-10212Medium· 6.3AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
CVE-2026-7579High· 7.3AstrBot Makes Use of Hard-coded Password
CVE-2025-48957High· 7.5AstrBot Has Path Traversal Vulnerability in /api/chat/get_file