Junglewise Threat Intelligence

CVE-2026-15501: AstrBotDevs AstrBot SSRF in MCP Test Endpoint

CVE-2026-15501 · Severity: medium · CVSS 6.3 · Published 2026-07-12

Technologies: AstrBotDevs Astrbot.

Executive brief

AstrBot, a chatbot management platform, contains a security flaw in its dashboard's tool testing feature. An authorized user can trick the server into making unauthorized network requests to internal systems or other websites. This could allow an attacker to scan internal networks, access private services, or disrupt internal operations that are normally protected from the outside world.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in AstrBot up to version 4.25.2 within the `ToolsRoute.test_mcp_connection` function in `astrbot/dashboard/routes/tools.py`. The endpoint `POST /api/tools/mcp/test` accepts a JSON payload containing an `mcp_server_config.url` parameter which is passed to `_quick_test_mcp_connection` without sufficient validation of the scheme, hostname, or destination IP. An authenticated attacker can provide a malicious URL (e.g., targeting loopback or RFC1918 addresses) to probe internal network services or access cloud metadata endpoints. The vulnerability is exploitable even if the subsequent MCP handshake fails, as the initial HTTP request is issued by the `aiohttp` client during the connection test. As of the advisory date, the vendor has not responded to the disclosure.

Affected products

  • AstrBotDevs AstrBot <= 4.25.2

Timeline

  • 2026-06-01: disclosed: Initial researcher disclosure via GitHub Gist
  • 2026-07-12: advisory: NVD/VulDB publication

References