These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization. The attack may be initiated remotely. The exploit is publicly available. This vulnerability has a CVSS score of 2.1 and a severity of LOW. Users of AstrBotDevs AstrBot up to 4.25.5 s [truncated]
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. The function _normalize_rw_path in the file astrbot/core/tools/computer_tools/fs.py is impacted, leading to a link following issue. The attack requires local access and has been made public. Users of AstrBotDevs AstrBot up to 4.25.5 should be aware of this vulnerability and take necessary precautions. The vendor was contacted early about this [truncated]
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username leads to authentication bypass by spoofing. It is possible to launch the attack remotely. The vulnerability has a CVSS score of 2.1 and is considered low severity.
A low-severity vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. This issue allows remote attackers to bypass authorization via manipulation of the Username argument in the OpenApiRoute.get_chat_sessions function. The exploit has been made public. The vulnerability class is related to authorization bypass, and the likely operational impact is low due to the low CVSS score of 2.1. The source con [truncated]
A server-side request forgery vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. The vulnerability affects the plugin update handler, specifically the update_plugin and update_all_plugins functions in the astrbot/dashboard/routes/plugin.py file. The manipulation of the download_url, download_urls, or proxy arguments results in server-side request forgery. The attack may be performed remotely. [truncated]
A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function Star.text_to_image/NetworkRenderStrategy.render of the file astrbot/core/star/base.py of the component T2I Feature. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. This vulnerability has been publicly disclosed, and although the vendor wa [truncated]
A server-side request forgery vulnerability has been identified in AstrBotDevs AstrBot up to 4.25.2. The vulnerability affects the function get_online_plugins of the file astrbot/dashboard/routes/plugin.py of the component market_list Endpoint. An attacker can exploit this vulnerability by manipulating the argument custom_registry, leading to server-side request forgery. The attack can be executed remotel [truncated]
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. The vulnerability is located in the Scheduled Task Handler component, specifically in the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py. The manipulation of the argument payload[note] results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the publ [truncated]
A low-severity authorization bypass vulnerability in AstrBot 4.24.2 allows remote attackers to bypass authorization controls by manipulating the session_id argument in the astr_main_agent function of astrbot/core/astr_main_agent.py. The CVSS 4.0 score of 2.1 reflects limited privileges required and low impact on confidentiality, integrity, and availability. The exploit has been publicly disclosed via a Gi [truncated]