Executive brief
AstrBot, a chatbot framework, is vulnerable to a system prompt injection flaw. An authorized user can upload a specially crafted skill file that bypasses security filters to hijack the underlying Large Language Model (LLM). This allows an attacker to override the bot's instructions, potentially leading to unauthorized data access or the execution of malicious commands.
Technical details
A system prompt injection vulnerability exists in AstrBot 4.23.6 within the `build_skills_prompt()` function in `astrbot/core/skills/skill_manager.py`. While the application includes a `_sanitize_prompt_description()` function designed to strip backticks and collapse newlines, this sanitization is only applied to skills with a `source_type` of `sandbox_only`. Skills uploaded locally via the dashboard are assigned a `source_type` of `local_only`, bypassing these checks. An authenticated attacker can upload a ZIP archive containing a `SKILL.md` file with a YAML literal block scalar in the description field. This allows the injection of multiline instructions and markdown code fences into the LLM's system prompt, enabling the attacker to break out of the skill description context and issue arbitrary directives to the model.
Affected products
- AstrBotDevs AstrBot 4.23.6
Timeline
- 2026-04-29: disclosed: Initial discovery and Gist publication
- 2026-06-01: advisory: CVE published via VulDB/NVD