PT-2026-57545 · Astrbotdevs · Astrbot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AstrBotDevs AstrBot versions prior to 4.25.3
Description
A server-side request forgery (SSRF) exists in the
market list endpoint. This occurs within the get online plugins() function located in the astrbot/dashboard/routes/plugin.py file. A remote attacker can trigger this issue by manipulating the custom registry argument, allowing the server to make unauthorized requests.Recommendations
Update AstrBotDevs AstrBot to a version newer than 4.25.2.
As a temporary mitigation, restrict access to the
market list endpoint or avoid using the custom registry argument until the software is updated.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astrbot