Vulnerabilities in AstrBotDevs

21 results
Vexday analysis

AstrBotDevs apresenta volume elevado de vulnerabilidades recentes, com 15 das 19 CVEs publicadas nos últimos 90 dias, indicando pressão contínua de correções. Embora nenhuma esteja sob ataque ativo (KEV) ou classificada como crítica no momento, a fraqueza dominante em controle de acesso impróprio (CWE-285) sugere risco potencial de comprometimento de privilégios. A concentração de descobertas recentes requer monitoramento próximo de possíveis exploits.

CVE-2026-6118MEDIUMAstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injectionEPSS 2.3%CVE-2025-48957HIGHAstrBot Has Path Traversal Vulnerability in /api/chat/get_fileEPSS 0.6%CVE-2026-10213MEDIUMAstrBotDevs AstrBot API Endpoint delete path traversalEPSS 0.4%CVE-2026-17530MEDIUMAstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorizationEPSS 0.4%CVE-2026-17529MEDIUMAstrBotDevs AstrBot astr_main_agent.py authorizationEPSS 0.4%CVE-2026-8754MEDIUMAstrBotDevs AstrBot File Upload chat.py post_file path traversalEPSS 0.4%CVE-2026-6984MEDIUMAstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engineEPSS 0.3%CVE-2026-16076MEDIUMAstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofingEPSS 0.3%CVE-2026-7579MEDIUMAstrBotDevs AstrBot Dashboard auth.py hard-coded credentialsEPSS 0.3%CVE-2026-6119MEDIUMAstrBotDevs AstrBot API Endpoint post_data.get server-side request forgeryEPSS 0.3%CVE-2026-10210MEDIUMAstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injectionEPSS 0.2%CVE-2026-6117MEDIUMAstrBotDevs AstrBot install-upload Endpoint plugin.py install_plugin_upload sandboxEPSS 0.2%CVE-2026-16075MEDIUMAstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorizationEPSS 0.2%CVE-2026-10212MEDIUMAstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorizationEPSS 0.2%CVE-2026-15500MEDIUMAstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgeryEPSS 0.2%CVE-2026-15501MEDIUMAstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgeryEPSS 0.2%CVE-2026-10211MEDIUMAstrBotDevs AstrBot fs.py _normalize_rw_path authorizationEPSS 0.2%CVE-2026-15499MEDIUMAstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorizationEPSS 0.2%CVE-2026-16074MEDIUMAstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgeryEPSS 0.2%CVE-2026-16073MEDIUMAstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scriptingEPSS 0.2%