astrbot has 7 CVEs on record between 2025 and 2026. The median CVSS is 6.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
Products
- astrbot 7
Worst active — by depth score
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability41CVE-2025-48957High· 7.5AstrBot Has Path Traversal Vulnerability in /api/chat/get_file41CVE-2026-7579High· 7.3AstrBot Makes Use of Hard-coded Password40CVE-2026-10212Medium· 6.3AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass35CVE-2026-8754Medium· 6.3AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py35
astrbot vulnerabilities
CVEs affecting astrbot, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-10212Medium· 6.3AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
CVE-2026-8754Medium· 6.3AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
CVE-2026-7579High· 7.3AstrBot Makes Use of Hard-coded Password
AstrBot Makes Use of Hard-coded Password
CVE-2026-6984Medium· 4.7AstrBot has Incomplete Filtering of Special Elements
AstrBot has Incomplete Filtering of Special Elements
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability
AstrBot contains a directory traversal vulnerability
CVE-2025-57697MediumAstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
CVE-2025-48957High· 7.5AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file