Executive brief
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Affected products
- PyPI astrbot
Junglewise Threat Intelligence
CVE-2025-57697 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: astrbot (PyPI). Vendors: PyPI.
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64