PT-2026-57545 · Astrbotdevs · Astrbot

·

CVE-2026-15500

·

Published

2026-07-12

·

Updated

2026-07-12

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AstrBotDevs AstrBot versions prior to 4.25.3
Description A server-side request forgery (SSRF) exists in the market list endpoint. This occurs within the get online plugins() function located in the astrbot/dashboard/routes/plugin.py file. A remote attacker can trigger this issue by manipulating the custom registry argument, allowing the server to make unauthorized requests.
Recommendations Update AstrBotDevs AstrBot to a version newer than 4.25.2. As a temporary mitigation, restrict access to the market list endpoint or avoid using the custom registry argument until the software is updated.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15500

Affected Products

Astrbot