PT-2026-57544 · Astrbotdevs · Astrbot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AstrBotDevs AstrBot versions prior to 4.25.3
Description
An improper authorization issue exists in the Scheduled Task Handler component within the
FutureTaskTool.call() function of the astrbot/core/tools/cron tools.py file. A remote attacker can exploit this by manipulating the payload["note"] variable, allowing for unauthorized access or actions.Recommendations
Update AstrBotDevs AstrBot to a version newer than 4.25.2.
As a temporary mitigation, restrict access to the
FutureTaskTool.call() function.Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astrbot