PT-2026-45244 · Astrbotdevs · Astrbot
Eric-A
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-10212
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AstrBotDevs AstrBot version 4.24.2
Description
An authorization bypass exists that can be triggered remotely. The issue occurs within the
astr main agent() function located in the astrbot/core/astr main agent.py file, where manipulation of the session id argument allows an attacker to bypass security checks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
astr main agent() function or monitor the session id argument for suspicious manipulation.Exploit
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astrbot