PT-2026-60877 · Astrbotdevs · Astrbot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AstrBotDevs AstrBot versions prior to 4.25.3
Description
A server-side request forgery exists in the Plugin Update Handler component within the file astrbot/dashboard/routes/plugin.py. A remote attacker can manipulate the
download url, download urls, or proxy arguments in the update plugin() or update all plugins() functions to induce the server to make unauthorized requests.Recommendations
Update AstrBotDevs AstrBot to version 4.25.3 or later.
As a temporary workaround, restrict access to the
update plugin() and update all plugins() functions until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astrbot