AstrBot vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-10212LowAstrBot: AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypassCVE-2026-8754LowAstrBot: AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.pyCVE-2026-7579MediumAstrBot: AstrBot Makes Use of Hard-coded PasswordCVE-2026-6984LowAstrBot: AstrBot has Incomplete Filtering of Special ElementsCVE-2025-55449Criticalastrbot: AstrBot is vulnerable to RCE with hard-coded JWT signing keysCVE-2025-57697MediumAstrBot: AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64CVE-2025-57698HighAstrBot: AstrBot contains a directory traversal vulnerabilityCVE-2025-48957Highastrbot: AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

Stop the waste.
Protect your environment with Kodem.