AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Modified: 6/29/2026
package
pkg:pypi/astrbot
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Modified: 6/29/2026
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
Modified: 9/10/2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Modified: 7/13/2026
AstrBot has Incomplete Filtering of Special Elements
Modified: 7/13/2026
AstrBot Makes Use of Hard-coded Password
Modified: 7/13/2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Modified: 7/13/2026
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Modified: 7/7/2026
AstrBot contains a directory traversal vulnerability
Modified: 7/7/2026
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
Modified: 7/7/2026
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Modified: 7/7/2026
AstrBot contains a directory traversal vulnerability
Modified: 7/7/2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Modified: 7/13/2026
AstrBot has Incomplete Filtering of Special Elements
Modified: 7/13/2026
AstrBot Makes Use of Hard-coded Password
Modified: 7/13/2026
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
Modified: 7/13/2026
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Modified: 7/1/2026