📦 Astrbot

by Astrbot

🔍 What is Astrbot?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-57698

HIGH CVSS 7.5 Nov 7, 2025

AstrBot Project v3.5.22 contains a directory traversal vulnerability in the plugin upload interface. Attackers can upload files to arbitrary locations on the server filesystem by manipulating filename...

CVE-2025-48957

HIGH CVSS 7.5 Jun 2, 2025

A path traversal vulnerability in AstrBot versions 3.4.4 through 3.5.12 allows attackers to access sensitive files like API keys and passwords. This affects all users running vulnerable versions of th...

CVE-2025-57697

MEDIUM CVSS 6.5 Nov 7, 2025

AstrBot Project v3.5.22 contains an arbitrary file read vulnerability in the _encode_image_bs64 function that allows attackers to read any file on the server by manipulating image paths. This affects ...