PT-2025-23500 · Astrbot · Astrbot

·

CVE-2025-48957

·

Published

2025-06-02

·

Updated

2026-07-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AstrBot versions 3.4.4 through 3.5.12
Description AstrBot is a large language model chatbot and development framework. A path traversal vulnerability may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676 and is included in version 3.5.13.
Recommendations For AstrBot versions 3.4.4 through 3.5.12, as a temporary workaround, users can edit the cmd config.json file to disable the dashboard feature. However, it is strongly recommended to upgrade to version 3.5.13 or later to fully resolve this issue.

Exploit

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48957
GHSA-CQ37-G2QP-3C2P
PYSEC-2026-1196

Affected Products

Astrbot