Executive brief
AstrBot is a chatbot management platform and dashboard. A security flaw in its API allows users with basic chat permissions to impersonate an administrator by spoofing their username in specific requests. This allows an attacker to execute administrative commands, potentially leading to unauthorized configuration changes or access to sensitive system functions.
Technical details
An authentication bypass by spoofing (CWE-290) exists in AstrBot up to version 4.25.5. The vulnerability is located in the `OpenApiRoute.chat_send` function within `astrbot/dashboard/routes/open_api.py`. While the API-key middleware initially authenticates the caller, the `chat_send` handler subsequently overwrites the trusted principal (`g.username`) with an untrusted `username` value provided in the JSON request body. This spoofed identity is then propagated to the message pipeline, where authorization checks for administrative commands are performed based on the sender ID. An attacker with a valid 'chat' scope API key can set their username to a known administrator ID (e.g., 'astrbot') to execute restricted commands. As of the advisory date, the vendor has not responded to the disclosure.
Affected products
- AstrBotDevs AstrBot up to 4.25.5
Timeline
- 2026-06-09: disclosed: Initial disclosure via GitHub Gist by researcher YLChen-007
- 2026-07-18: advisory: NVD/VulDB publication date