AstrBot
AI Agent Assistant & development framework that integrates lots of IM platforms, LLMs, plugins and AI feature, and can be your openclaw alternative. ✨
Activity
- Latest release
- 14h ago
- Total releases
- 168
- Cadence
- ~daily
- Last 12 months
- 130
Reach
- Stars
- 40.5k
Details
- License
- unknown
- First release
- May 01, 2025
| Version | Released | |
|---|---|---|
4.28.1
patch
| ||
4.28.0
minor
| ||
4.28.0b1
pre
| ||
4.27.5
patch
| ||
4.27.4
patch
| ||
4.27.3
patch
| ||
4.27.2
patch
| ||
4.27.1
patch
| ||
4.27.0
minor
| ||
4.26.8
patch
| ||
4.26.7
patch
| ||
4.26.6
patch
| ||
4.26.5
patch
| ||
4.26.4
patch
| ||
4.26.3
patch
| ||
4.26.2
patch
| ||
4.26.1
patch
| ||
4.26.0
minor
| ||
4.25.6
patch
| ||
4.25.6rc3
pre
| ||
4.25.6rc2
pre
| ||
4.25.6rc1
pre
| ||
4.26.0b12
pre
| ||
4.26.0b11
pre
| ||
4.26.0b10
pre
| ||
4.26.0b9
pre
| ||
4.26.0b8
pre
| ||
4.26.0b7
pre
| ||
4.26.0b6
pre
| ||
4.26.0b5
pre
| ||
4.26.0b4
pre
| ||
4.26.0b3
pre
| ||
4.26.0b2
pre
| ||
4.26.0b1
pre
| ||
4.25.5
patch
| ||
4.25.4
patch
| ||
4.25.3
patch
| ||
4.25.2
patch
| ||
4.25.1
patch
| ||
4.25.0
minor
| ||
4.24.5
patch
| ||
4.24.4
patch
| ||
4.24.3
patch
| ||
4.24.2
patch
1 CVE
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
4.24.1
patch
1 CVE
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
4.24.0
minor
1 CVE
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
4.23.6
patch
1 CVE
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
4.23.5
patch
2 CVEs
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-8754
PYSEC-2026-2380
GHSA-f63h-wc26-pmvc
Jul 13, 2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Medium
Network
Low
Low
None
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulation of the argument filename results in path traversal. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 4.23.6 is recommended to address this issue. The patch is identified as aaec41e5054569ceaa1113593a34da7568e2d211. You should upgrade the affected component. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 109 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
Fixed in
4.23.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.23.3
patch
2 CVEs
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-8754
PYSEC-2026-2380
GHSA-f63h-wc26-pmvc
Jul 13, 2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Medium
Network
Low
Low
None
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulation of the argument filename results in path traversal. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 4.23.6 is recommended to address this issue. The patch is identified as aaec41e5054569ceaa1113593a34da7568e2d211. You should upgrade the affected component. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 109 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
Fixed in
4.23.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
4.23.2
patch
2 CVEs
CVE-2026-10212
PYSEC-2026-2383
GHSA-r6vm-4xwg-w69h
Jul 13, 2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Medium
Network
Low
Low
None
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 113 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.23.6
4.24.0
4.24.1
4.24.2
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-8754
PYSEC-2026-2380
GHSA-f63h-wc26-pmvc
Jul 13, 2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Medium
Network
Low
Low
None
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulation of the argument filename results in path traversal. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 4.23.6 is recommended to address this issue. The patch is identified as aaec41e5054569ceaa1113593a34da7568e2d211. You should upgrade the affected component. Affected versions
3.4.39
3.5.10
3.5.11
3.5.12
3.5.13
3.5.14
3.5.15
3.5.17
3.5.18
3.5.19
3.5.20
3.5.21
+ 109 more Show less
3.5.22
3.5.23
3.5.24
3.5.25
3.5.26
3.5.27
3.5.6
3.5.7
3.5.8
3.5.9
4.0.0
4.0.0b1
4.0.0b2
4.0.0b3
4.0.0b4
4.0.0b5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.10.0
4.10.0a1
4.10.0a2
4.10.1
4.10.2
4.10.3
4.10.4
4.10.5
4.10.6
4.11.0
4.11.1
4.11.2
4.11.3
4.11.4
4.12.0
4.12.1
4.12.2
4.12.3
4.12.4
4.13.0
4.13.1
4.13.2
4.14.0
4.14.1
4.14.2
4.14.3
4.14.4
4.14.5
4.14.6
4.14.7
4.14.8
4.15.0
4.16.0
4.17.0
4.17.1
4.17.2
4.17.3
4.17.4
4.17.5
4.17.6
4.18.0
4.18.1
4.18.2
4.18.3
4.19.2
4.19.3
4.19.4
4.19.5
4.2.0
4.2.1
4.20.0
4.20.1
4.21.0
4.22.0
4.22.1
4.22.2
4.22.3
4.23.0
4.23.0b1
4.23.1
4.23.2
4.23.3
4.23.5
4.3.0
4.3.1
4.3.2
4.3.3
4.3.5
4.5.0
4.5.1
4.5.2
4.5.3
4.5.6
4.5.7
4.5.8
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.7.4
4.8.0
4.9.0
4.9.1
4.9.2
Fixed in
4.23.6
References
Updated Jul 13, 2026 · Source: OSV.dev |