PT-2025-45777 · Pypi · Astrbot

Published

2025-11-07

·

Updated

2025-11-07

CVSS v4.0

5.6

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function encode image bs64. Since the encode image bs64 function defined in entities.py opens the image specified by the user in the request body and returns the image content as a base64-encoded string without checking the legitimacy of the image path, attackers can construct a series of malicious URLs to read any specified file, resulting in sensitive data leakage.

Fix

Out of bounds Read

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-VM2F-46XC-5JC3

Affected Products

Astrbot