Astrbotdevs · Astrbot · CVE-2026-16074
**Name of the Vulnerable Software and Affected Versions**
AstrBotDevs AstrBot versions prior to 4.25.3
**Description**
A server-side request forgery exists in the Plugin Update Handler component within the file astrbot/dashboard/routes/plugin.py. A remote attacker can manipulate the `download url`, `download urls`, or `proxy` arguments in the `update plugin()` or `update all plugins()` functions to induce the server to make unauthorized requests.
**Recommendations**
Update AstrBotDevs AstrBot to version 4.25.3 or later.
As a temporary workaround, restrict access to the `update plugin()` and `update all plugins()` functions until the update is applied.