Junglewise Threat Intelligence

CVE-2026-16073: AstrBotDevs AstrBot XSS in T2I Feature

CVE-2026-16073 · Severity: low · CVSS 3.5 · Published 2026-07-17

Technologies: AstrBotDevs Astrbot.

Executive brief

AstrBot, a chatbot framework, contains a security flaw in its text-to-image (T2I) feature which converts long text replies into images. An attacker can send specially crafted messages that break out of the image-generation template to execute malicious scripts in the context of the image renderer. This could allow an attacker to tamper with generated content or falsify information presented to users.

Technical details

A cross-site scripting (XSS) vulnerability exists in AstrBot's T2I feature within the `Star.text_to_image` and `NetworkRenderStrategy.render` functions in `astrbot/core/star/base.py`. The root cause is the use of the `| safe` filter in Jinja2 templates (such as `base.html`), which disables HTML escaping for the `text` variable. An attacker with the ability to provide input to the T2I renderer (e.g., via authenticated chat or API flows) can inject a payload like `</textarea><script>alert(1)</script>` to break out of the hidden textarea container. This results in script execution within the remote or browser-based renderer context. While the vendor was contacted, no patch has been confirmed at the time of disclosure.

Affected products

  • AstrBotDevs AstrBot up to 4.25.2

Timeline

  • 2026-06-09: disclosed: Initial discovery and Gist publication
  • 2026-07-17: advisory: CVE-2026-16073 published via VulDB/NVD

References