Astrbot
This hub aggregates every CVE we track for Astrbot, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
24
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM19HIGH4LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
2
0
0
0
0
4
3
4
10
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Astrbot.
- CVE-2026-17530AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization6.3
- CVE-2026-17529AstrBotDevs AstrBot astr_main_agent.py authorization6.3
- CVE-2026-16077AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following5.3
- CVE-2026-16076AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing6.3
- CVE-2026-16075AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization4.3
- CVE-2026-16074AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery6.3
- CVE-2026-16073AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting3.5
- CVE-2026-15501AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery6.3
- CVE-2026-15500AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery6.3
- CVE-2026-15499AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization6.3
- CVE-2026-10213AstrBotDevs AstrBot API Endpoint delete path traversal5.4
- CVE-2026-10212AstrBotDevs AstrBot astr_main_agent.py astr_main_agent authorization6.3
- CVE-2026-10211AstrBotDevs AstrBot fs.py _normalize_rw_path authorization6.3
- CVE-2026-10210AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection6.3
- CVE-2026-8754AstrBotDevs AstrBot File Upload chat.py post_file path traversal6.3
Product normalization is registry-driven with AI assist and human review. How it works