Product
astrbot
4 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-55449
CVE-2025-57697
CVE-2025-57698
CVE-2025-48957
all versions
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign
all versions
AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image_bs64 func
all versions
AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface
>= 3.4.4 and < 3.5.13
AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 thro