PT-2026-45244 · Astrbotdevs · Astrbot

Eric-A

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-10212

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AstrBotDevs AstrBot version 4.24.2
Description An authorization bypass exists that can be triggered remotely. The issue occurs within the astr main agent() function located in the astrbot/core/astr main agent.py file, where manipulation of the session id argument allows an attacker to bypass security checks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the astr main agent() function or monitor the session id argument for suspicious manipulation.

Exploit

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10212

Affected Products

Astrbot