PT-2026-64974 · Astrbotdevs+1 · Astrbot

·

CVE-2026-17529

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AstrBotDevs AstrBot versions prior to 4.25.6
Description Remote manipulation of the req.func tool argument within a function in the astrbot/core/astr main agent.py file leads to incorrect authorization.
Recommendations Install the patch identified as d23011262e8e75e1ec41b0f1f0091493a022327e for versions prior to 4.25.6.

Exploit

Fix

Improper Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17529

Affected Products

Astrbot