PT-2025-23500 · Astrbot · Astrbot
Raven95676
+1
·
Published
2025-06-02
·
Updated
2025-06-25
·
CVE-2025-48957
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AstrBot versions 3.4.4 through 3.5.12
Description
AstrBot is a large language model chatbot and development framework. A path traversal vulnerability may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676 and is included in version 3.5.13.
Recommendations
For AstrBot versions 3.4.4 through 3.5.12, as a temporary workaround, users can edit the
cmd config.json file to disable the dashboard feature.
However, it is strongly recommended to upgrade to version 3.5.13 or later to fully resolve this issue.Exploit
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astrbot