Junglewise Threat Intelligence

CVE-2026-15500: AstrBotDevs AstrBot SSRF in market_list endpoint

CVE-2026-15500 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: AstrBotDevs Astrbot.

Executive brief

AstrBot, a chatbot management platform, contains a security flaw in its plugin marketplace dashboard. An authenticated user can trick the server into making unauthorized network requests to internal systems or other websites. This could allow an attacker to scan internal networks, access private administrative interfaces, or interact with sensitive cloud metadata services that are normally protected from the outside world.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in AstrBot versions up to 4.25.2 within the `get_online_plugins` function in `astrbot/dashboard/routes/plugin.py`. The application accepts an untrusted `custom_registry` URL parameter via the `/api/plugin/market_list` endpoint and uses it directly in `aiohttp` requests without validation or filtering. An authenticated attacker can provide a malicious URL (including loopback or internal RFC1918 addresses) which the server will then fetch. The vulnerability also derives a second request to an MD5 endpoint based on the same attacker-controlled input. This allows for internal port scanning and interaction with services reachable only from the AstrBot host, such as cloud metadata endpoints or local management APIs. No patch was available at the time of disclosure.

Affected products

  • AstrBotDevs AstrBot <= 4.25.2

Timeline

  • 2026-06-01: disclosed: Initial researcher disclosure via GitHub Gist
  • 2026-07-12: advisory: NVD/VulDB publication

References