Technology · PyPI
astrbot (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in astrbot (PyPI): 0 in the last 7 days and 15 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-17530, was published on 27 July 2026.
- Last 7 days
- 0
- Last 90 days
- 15
- Critical, all time
- 1
- Exploited in the wild
- 0
About astrbot (PyPI)
AstrBot is a chatbot framework and management tool distributed via the Python Package Index.
Latest astrbot (PyPI) vulnerabilities
- CVE-2026-17530: AstrBotDevs AstrBot incorrect authorization in Subagent tool handoffmediumCVSS 6.3
- CVE-2026-17529: AstrBotDevs AstrBot incorrect authorization in astr_main_agent.pymediumCVSS 6.3
- CVE-2026-16077: AstrBotDevs AstrBot link following in Filesystem Computer-Use ToolmediumCVSS 5.3
- CVE-2026-16076: AstrBotDevs AstrBot authentication bypass via spoofing in OpenAPImediumCVSS 6.3
- CVE-2026-16075: AstrBotDevs AstrBot authorization bypass in session-listing endpointmediumCVSS 4.3
- CVE-2026-16074: AstrBotDevs AstrBot SSRF in Plugin Update HandlermediumCVSS 6.3
- CVE-2026-16073: AstrBotDevs AstrBot XSS in T2I FeaturelowCVSS 3.5
- CVE-2026-7579: PYSEC-2026-2382 - AstrBot Makes Use of Hard-coded PasswordlowCVSS 3.1EPSS 0.5%
- CVE-2026-6984: PYSEC-2026-2381 - AstrBot has Incomplete Filtering of Special ElementslowCVSS 3.1EPSS 0.4%
- CVE-2026-15501: AstrBotDevs AstrBot SSRF in MCP Test EndpointmediumCVSS 6.3
- CVE-2026-15500: AstrBotDevs AstrBot SSRF in market_list endpointmediumCVSS 6.3
- CVE-2026-15499: AstrBotDevs AstrBot improper authorization in Scheduled Task HandlermediumCVSS 6.3
- CVE-2025-57697: PYSEC-2026-1197 - AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64mediumCVSS 4EPSS 0.3%
- CVE-2025-57698: PYSEC-2026-1198 - AstrBot contains a directory traversal vulnerabilitymediumCVSS 4EPSS 0.8%
- CVE-2025-48957: PYSEC-2026-1196 - AstrBot Has Path Traversal Vulnerability in /api/chat/get_filelowCVSS 3.1EPSS 0.7%
- CVE-2026-10213: AstrBotDevs AstrBot path traversal in /api/skills/deletemediumCVSS 5.4
- CVE-2026-10212: AstrBotDevs AstrBot authorization bypass via delimiter injection in session_idmediumCVSS 6.3EPSS 0.2%
- CVE-2026-10211: AstrBotDevs AstrBot incorrect authorization in filesystem toolsmediumCVSS 6.3
- CVE-2026-10210: AstrBotDevs AstrBot prompt injection in skill_manager.pymediumCVSS 6.3
- CVE-2026-8754: AstrBotDevs AstrBot path traversal in file upload handlermediumCVSS 6.3EPSS 0.4%
- CVE-2025-55449: AstrBotDevs AstrBot hardcoded JWT secret keycriticalCVSS 9.8EPSS 0.3%
Most severe astrbot (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-55449: AstrBotDevs AstrBot hardcoded JWT secret keycriticalCVSS 9.8EPSS 0.3%
- CVE-2026-8754: AstrBotDevs AstrBot path traversal in file upload handlermediumCVSS 6.3EPSS 0.4%
- CVE-2026-10212: AstrBotDevs AstrBot authorization bypass via delimiter injection in session_idmediumCVSS 6.3EPSS 0.2%
- CVE-2026-17530: AstrBotDevs AstrBot incorrect authorization in Subagent tool handoffmediumCVSS 6.3
- CVE-2026-17529: AstrBotDevs AstrBot incorrect authorization in astr_main_agent.pymediumCVSS 6.3
- CVE-2026-16076: AstrBotDevs AstrBot authentication bypass via spoofing in OpenAPImediumCVSS 6.3
- CVE-2026-16074: AstrBotDevs AstrBot SSRF in Plugin Update HandlermediumCVSS 6.3
- CVE-2026-15501: AstrBotDevs AstrBot SSRF in MCP Test EndpointmediumCVSS 6.3
- CVE-2026-15500: AstrBotDevs AstrBot SSRF in market_list endpointmediumCVSS 6.3
- CVE-2026-15499: AstrBotDevs AstrBot improper authorization in Scheduled Task HandlermediumCVSS 6.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 7 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/astrbot.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "astrbot (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/astrbot, 26 September 2026.