Junglewise Threat Intelligence

CVE-2026-10213: AstrBotDevs AstrBot path traversal in /api/skills/delete

CVE-2026-10213 · Severity: medium · CVSS 5.4 · Published 2026-06-01

Technologies: AstrBotDevs Astrbot.

Executive brief

A security vulnerability exists in AstrBot, a chatbot framework. An attacker with basic user access can exploit a flaw in the skill deletion feature to delete arbitrary folders on the server's file system. This could lead to data loss or service disruption by removing critical application files.

Technical details

A path traversal vulnerability (CWE-22) exists in AstrBot 4.23.6 within the API endpoint `/api/skills/delete`. The application fails to properly sanitize the 'Name' argument, allowing an attacker to use directory traversal sequences (e.g., '../') to escape the intended directory. A remote attacker with low privileges (authenticated user) can exploit this to delete arbitrary directories on the host system. A public exploit has been released, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • AstrBotDevs AstrBot 4.23.6

Timeline

  • 2026-05-06: other: Public exploit code released on GitHub Gist
  • 2026-06-01: advisory: CVE published by VulDB/NVD

References