PT-2026-64992 · Astrbotdevs · Astrbot
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AstrBotDevs AstrBot versions prior to 4.25.6
Description
A security flaw in the Subagent component allows for incorrect authorization. The issue resides in the
build handoff toolset() function within the AstrBot/astrbot/core/astr agent tool exec.py file. This flaw can be exploited remotely.Recommendations
Apply patch d23011262e8e75e1ec41b0f1f0091493a022327e to remediate the issue.
As a temporary workaround, restrict access to the
build handoff toolset() function to minimize the risk of exploitation.Exploit
Fix
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astrbot