PatchSiren cyber security CVE debrief
CVE-2026-8754 Unknown Vendor CVE debrief
CVE-2026-8754 is a remote path traversal issue in AstrBot’s file upload handler, specifically the post_file function in astrbot/dashboard/routes/chat.py. The supplied record says the filename argument can be manipulated to affect file paths, and it notes that a public exploit is available. The affected range is AstrBot up to 4.23.5, with 4.23.6 identified as the fix release.
- Vendor
- Unknown Vendor
- Product
- Unknown
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-17
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-17
- Advisory updated
- 2026-05-18
Who should care
Administrators and operators running AstrBot up to 4.23.5, especially if the dashboard or upload functionality is reachable from untrusted networks or by users who should not be able to control upload filenames.
Technical summary
The vulnerability is described as a CWE-22 path traversal issue in the file upload handler. The affected code path is post_file in astrbot/dashboard/routes/chat.py, where unsafely handled filename input can lead to traversal outside the intended directory. The source corpus identifies commit aaec41e5054569ceaa1113593a34da7568e2d211 and release v4.23.6 as the remediation reference.
Defensive priority
Low CVSS score, but patch promptly because the issue is remotely reachable and the source record indicates a public exploit. Prioritize systems that expose the dashboard or file upload route.
Recommended defensive actions
- Upgrade AstrBot to version 4.23.6 or later.
- Review any deployments still on 4.23.5 or earlier and schedule immediate remediation.
- Restrict access to dashboard and upload endpoints until patched, especially on internet-facing systems.
- Validate that uploaded filenames are normalized and constrained to intended directories in any local customizations or forks.
- Monitor for abnormal file-write behavior around the AstrBot upload workflow after exposure.
Evidence notes
All claims are drawn from the supplied record and its listed references. The record states: affected versions are up to 4.23.5, the issue is in post_file within astrbot/dashboard/routes/chat.py, the input involved is filename, the weakness class is CWE-22, a public exploit is noted, and 4.23.6 plus commit aaec41e5054569ceaa1113593a34da7568e2d211 are the fix references. The vendor mapping in the supplied data is low confidence, so product identification should be treated as source-driven rather than fully normalized.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8754 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8754
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8754 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8754
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/YLChen-007/054415c2b63e58813328bc879a90c504
-
Source reference
Unverified legacy reference
URL: https://github.com/AstrBotDevs/AstrBot/
-
Source reference
Unverified legacy reference
URL: https://github.com/AstrBotDevs/AstrBot/commit/aaec41e5054569ceaa1113593a34da7568e2d211
-
Source reference
Unverified legacy reference
URL: https://github.com/AstrBotDevs/AstrBot/releases/tag/v4.23.6
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/811172
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/364381
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/364381/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.