Junglewise Threat Intelligence

CVE-2025-55449: AstrBotDevs AstrBot hardcoded JWT secret key

CVE-2025-55449 · Severity: critical · CVSS 9.8 · Published 2026-05-08

Technologies: astrbot (PyPI). Vendors: PyPI.

Executive brief

AstrBot, an AI agent and bot development framework, contains a security flaw where it uses a publicly known, permanent password (hardcoded key) to verify user identities. An attacker can use this known key to create fake digital credentials, allowing them to bypass security controls. This can lead to unauthorized access, the ability to upload malicious software, and full control over the bot and its connected platforms.

Technical details

AstrBot (up to version 3.5.17) utilizes a hardcoded secret key ('Advanced_System_for_Text_Response_and_Bot_Operations_Tool') for signing and validating JSON Web Tokens (JWT). Because this key is static and publicly available in the source code, an unauthenticated remote attacker can forge valid JWTs to impersonate administrative users. This authentication bypass can be leveraged to perform administrative actions, such as uploading malicious plugins, which leads to Remote Code Execution (RCE) on the underlying system. The vulnerability is classified as CWE-321 (Use of Hard-coded Cryptographic Key).

Affected products

  • AstrBotDevs AstrBot <= 3.5.17

Timeline

  • 2026-05-08: advisory: Initial disclosure of CVE-2025-55449

References

Related threats