Junglewise Threat Intelligence

CVE-2026-17529: AstrBotDevs AstrBot incorrect authorization in astr_main_agent.py

CVE-2026-17529 · Severity: medium · CVSS 6.3 · Published 2026-07-27

Technologies: AstrBotDevs Astrbot.

Executive brief

AstrBot is an AI agent development framework used to integrate LLMs with various messaging platforms. A security flaw allows users to bypass "persona" restrictions that are supposed to disable specific tools, such as web search. This means an attacker could force the AI to use tools and access information that the administrator explicitly intended to block.

Technical details

An incorrect authorization vulnerability exists in AstrBot up to version 4.25.5 within the 'astrbot/core/astr_main_agent.py' component. The root cause is a logic error where built-in tools (like web search) are appended to the agent's toolset after the persona-level filtering has already occurred. By manipulating the 'req.func_tool' argument, a remote authenticated user can bypass a persona's 'tools=[]' policy, re-exposing and invoking restricted tools. A patch has been released in commit d23011262e8e75e1ec41b0f1f0091493a022327e to enforce persona tool boundaries.

Affected products

  • AstrBotDevs AstrBot up to 4.25.5

Timeline

  • 2026-06-15: patched: Fix commit d23011262e8e75e1ec41b0f1f0091493a022327e authored.
  • 2026-07-27: advisory: Vulnerability disclosed and CVE assigned.

References