astrbot vulnerabilities
CVEs whose affected-version data names the astrbot package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2026-10212Medium· 6.3AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
▾ Sunlitastrbot · astrbotEPSS 0.21%via OSV
CVE-2026-8754Medium· 6.3AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
▾ Sunlitastrbot · astrbotEPSS 0.36%via OSV
CVE-2026-7579High· 7.3AstrBot Makes Use of Hard-coded Password
AstrBot Makes Use of Hard-coded Password
▾ Twilightastrbot · astrbotEPSS 0.29%via OSV
CVE-2026-6984Medium· 4.7AstrBot has Incomplete Filtering of Special Elements
AstrBot has Incomplete Filtering of Special Elements
▾ Sunlitastrbot · astrbotEPSS 0.30%via OSV
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability
AstrBot contains a directory traversal vulnerability
▾ Twilightastrbot · astrbotEPSS 0.78%via OSV
CVE-2025-57697MediumAstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
▾ Sunlitastrbot · astrbotEPSS 0.32%via OSV
CVE-2025-48957High· 7.5AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
▾ Twilightastrbot · astrbotEPSS 0.74%via OSV