PT-2026-64974 · Astrbotdevs+1 · Astrbot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AstrBotDevs AstrBot versions prior to 4.25.6
Description
Remote manipulation of the
req.func tool argument within a function in the astrbot/core/astr main agent.py file leads to incorrect authorization.Recommendations
Install the patch identified as d23011262e8e75e1ec41b0f1f0091493a022327e for versions prior to 4.25.6.
Exploit
Fix
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astrbot