{"schema_version":1,"title":"astrbot (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in astrbot (PyPI): 0 in the last 7 days and 15 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-17530, was published on 27 July 2026.","url":"https://junglewise.ai/threats/technologies/astrbot","json_url":"https://junglewise.ai/threats/technologies/astrbot.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/astrbot","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":21,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":15,"last_365_days":21},"latest":[{"cve":"CVE-2026-17530","cvss":6.3,"slug":"cve-2026-17530-astrbotdevs-astrbot-incorrect-authorization-in-subagent-tool","title":"AstrBotDevs AstrBot incorrect authorization in Subagent tool handoff","severity":"medium","exploited":false,"published_at":"2026-07-27T16:17:04.49+00:00","url":"https://junglewise.ai/threats/cve-2026-17530-astrbotdevs-astrbot-incorrect-authorization-in-subagent-tool"},{"cve":"CVE-2026-17529","cvss":6.3,"slug":"cve-2026-17529-astrbotdevs-astrbot-incorrect-authorization-in-astr-main-agent-py","title":"AstrBotDevs AstrBot incorrect authorization in astr_main_agent.py","severity":"medium","exploited":false,"published_at":"2026-07-27T16:17:04.31+00:00","url":"https://junglewise.ai/threats/cve-2026-17529-astrbotdevs-astrbot-incorrect-authorization-in-astr-main-agent-py"},{"cve":"CVE-2026-16077","cvss":5.3,"slug":"cve-2026-16077-astrbotdevs-astrbot-link-following-in-filesystem-computer-use","title":"AstrBotDevs AstrBot link following in Filesystem Computer-Use Tool","severity":"medium","exploited":false,"published_at":"2026-07-18T07:16:39.29+00:00","url":"https://junglewise.ai/threats/cve-2026-16077-astrbotdevs-astrbot-link-following-in-filesystem-computer-use"},{"cve":"CVE-2026-16076","cvss":6.3,"slug":"cve-2026-16076-astrbotdevs-astrbot-authentication-bypass-via-spoofing-in-openapi","title":"AstrBotDevs AstrBot authentication bypass via spoofing in OpenAPI","severity":"medium","exploited":false,"published_at":"2026-07-18T06:16:35.203+00:00","url":"https://junglewise.ai/threats/cve-2026-16076-astrbotdevs-astrbot-authentication-bypass-via-spoofing-in-openapi"},{"cve":"CVE-2026-16075","cvss":4.3,"slug":"cve-2026-16075-astrbotdevs-astrbot-authorization-bypass-in-session-listing","title":"AstrBotDevs AstrBot authorization bypass in session-listing endpoint","severity":"medium","exploited":false,"published_at":"2026-07-18T05:16:52.49+00:00","url":"https://junglewise.ai/threats/cve-2026-16075-astrbotdevs-astrbot-authorization-bypass-in-session-listing"},{"cve":"CVE-2026-16074","cvss":6.3,"slug":"cve-2026-16074-astrbotdevs-astrbot-ssrf-in-plugin-update-handler","title":"AstrBotDevs AstrBot SSRF in Plugin Update Handler","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:06.087+00:00","url":"https://junglewise.ai/threats/cve-2026-16074-astrbotdevs-astrbot-ssrf-in-plugin-update-handler"},{"cve":"CVE-2026-16073","cvss":3.5,"slug":"cve-2026-16073-astrbotdevs-astrbot-xss-in-t2i-feature","title":"AstrBotDevs AstrBot XSS in T2I Feature","severity":"low","exploited":false,"published_at":"2026-07-17T19:17:13.103+00:00","url":"https://junglewise.ai/threats/cve-2026-16073-astrbotdevs-astrbot-xss-in-t2i-feature"},{"cve":"CVE-2026-7579","cvss":3.1,"epss":0.005,"slug":"cve-2026-7579-astrbot-makes-use-of-hard-coded-password","title":"PYSEC-2026-2382 - AstrBot Makes Use of Hard-coded Password","severity":"low","exploited":false,"published_at":"2026-07-13T15:02:55.937569+00:00","url":"https://junglewise.ai/threats/cve-2026-7579-astrbot-makes-use-of-hard-coded-password"},{"cve":"CVE-2026-6984","cvss":3.1,"epss":0.0041,"slug":"cve-2026-6984-astrbot-has-incomplete-filtering-of-special-elements","title":"PYSEC-2026-2381 - AstrBot has Incomplete Filtering of Special Elements","severity":"low","exploited":false,"published_at":"2026-07-13T15:02:53.420297+00:00","url":"https://junglewise.ai/threats/cve-2026-6984-astrbot-has-incomplete-filtering-of-special-elements"},{"cve":"CVE-2026-15501","cvss":6.3,"slug":"cve-2026-15501-astrbotdevs-astrbot-ssrf-in-mcp-test-endpoint","title":"AstrBotDevs AstrBot SSRF in MCP Test Endpoint","severity":"medium","exploited":false,"published_at":"2026-07-12T13:16:36.633+00:00","url":"https://junglewise.ai/threats/cve-2026-15501-astrbotdevs-astrbot-ssrf-in-mcp-test-endpoint"},{"cve":"CVE-2026-15500","cvss":6.3,"slug":"cve-2026-15500-astrbotdevs-astrbot-ssrf-in-market-list-endpoint","title":"AstrBotDevs AstrBot SSRF in market_list endpoint","severity":"medium","exploited":false,"published_at":"2026-07-12T12:16:44.413+00:00","url":"https://junglewise.ai/threats/cve-2026-15500-astrbotdevs-astrbot-ssrf-in-market-list-endpoint"},{"cve":"CVE-2026-15499","cvss":6.3,"slug":"cve-2026-15499-astrbotdevs-astrbot-improper-authorization-in-scheduled-task","title":"AstrBotDevs AstrBot improper authorization in Scheduled Task Handler","severity":"medium","exploited":false,"published_at":"2026-07-12T12:16:44.257+00:00","url":"https://junglewise.ai/threats/cve-2026-15499-astrbotdevs-astrbot-improper-authorization-in-scheduled-task"},{"cve":"CVE-2025-57697","cvss":4,"epss":0.0032,"slug":"cve-2025-57697-astrbot-has-an-arbitrary-file-read-vulnerability-in-function","title":"PYSEC-2026-1197 - AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:09.964955+00:00","url":"https://junglewise.ai/threats/cve-2025-57697-astrbot-has-an-arbitrary-file-read-vulnerability-in-function"},{"cve":"CVE-2025-57698","cvss":4,"epss":0.0078,"slug":"cve-2025-57698-astrbot-contains-a-directory-traversal-vulnerability","title":"PYSEC-2026-1198 - AstrBot contains a directory traversal vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:09.885967+00:00","url":"https://junglewise.ai/threats/cve-2025-57698-astrbot-contains-a-directory-traversal-vulnerability"},{"cve":"CVE-2025-48957","cvss":3.1,"epss":0.0074,"slug":"cve-2025-48957-astrbot-has-path-traversal-vulnerability-in-api-chat-get-file","title":"PYSEC-2026-1196 - AstrBot Has Path Traversal Vulnerability in /api/chat/get_file","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:53.742707+00:00","url":"https://junglewise.ai/threats/cve-2025-48957-astrbot-has-path-traversal-vulnerability-in-api-chat-get-file"},{"cve":"CVE-2026-10213","cvss":5.4,"slug":"cve-2026-10213-astrbotdevs-astrbot-path-traversal-in-api-skills-delete","title":"AstrBotDevs AstrBot path traversal in /api/skills/delete","severity":"medium","exploited":false,"published_at":"2026-06-01T03:16:24.967+00:00","url":"https://junglewise.ai/threats/cve-2026-10213-astrbotdevs-astrbot-path-traversal-in-api-skills-delete"},{"cve":"CVE-2026-10212","cvss":6.3,"epss":0.0021,"slug":"cve-2026-10212-astrbotdevs-astrbot-authorization-bypass-via-delimiter-injection","title":"AstrBotDevs AstrBot authorization bypass via delimiter injection in session_id","severity":"medium","exploited":false,"published_at":"2026-06-01T03:16:23.837+00:00","url":"https://junglewise.ai/threats/cve-2026-10212-astrbotdevs-astrbot-authorization-bypass-via-delimiter-injection"},{"cve":"CVE-2026-10211","cvss":6.3,"slug":"cve-2026-10211-astrbotdevs-astrbot-incorrect-authorization-in-filesystem-tools","title":"AstrBotDevs AstrBot incorrect authorization in filesystem tools","severity":"medium","exploited":false,"published_at":"2026-06-01T02:16:17.713+00:00","url":"https://junglewise.ai/threats/cve-2026-10211-astrbotdevs-astrbot-incorrect-authorization-in-filesystem-tools"},{"cve":"CVE-2026-10210","cvss":6.3,"slug":"cve-2026-10210-astrbotdevs-astrbot-prompt-injection-in-skill-manager-py","title":"AstrBotDevs AstrBot prompt injection in skill_manager.py","severity":"medium","exploited":false,"published_at":"2026-06-01T02:16:17.543+00:00","url":"https://junglewise.ai/threats/cve-2026-10210-astrbotdevs-astrbot-prompt-injection-in-skill-manager-py"},{"cve":"CVE-2026-8754","cvss":6.3,"epss":0.0043,"slug":"cve-2026-8754-astrbotdevs-astrbot-path-traversal-in-file-upload-handler","title":"AstrBotDevs AstrBot path traversal in file upload handler","severity":"medium","exploited":false,"published_at":"2026-05-17T13:16:46.107+00:00","url":"https://junglewise.ai/threats/cve-2026-8754-astrbotdevs-astrbot-path-traversal-in-file-upload-handler"},{"cve":"CVE-2025-55449","cvss":9.8,"epss":0.0028,"slug":"cve-2025-55449-astrbot-hard-coded-jwt-key-authentication-bypass-and-rce","title":"AstrBotDevs AstrBot hardcoded JWT secret key","severity":"critical","exploited":false,"published_at":"2026-05-08T07:16:28.047+00:00","url":"https://junglewise.ai/threats/cve-2025-55449-astrbot-hard-coded-jwt-key-authentication-bypass-and-rce"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"astrbot (PyPI)","slug":"astrbot","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/astrbot/","repo_url":"https://github.com/ch8n/astrbot","description":"AstrBot is a chatbot framework and management tool distributed via the Python Package Index.","url":"https://junglewise.ai/threats/technologies/astrbot"},"most_severe":[{"cve":"CVE-2025-55449","cvss":9.8,"epss":0.0028,"slug":"cve-2025-55449-astrbot-hard-coded-jwt-key-authentication-bypass-and-rce","title":"AstrBotDevs AstrBot hardcoded JWT secret key","severity":"critical","exploited":false,"published_at":"2026-05-08T07:16:28.047+00:00","url":"https://junglewise.ai/threats/cve-2025-55449-astrbot-hard-coded-jwt-key-authentication-bypass-and-rce"},{"cve":"CVE-2026-8754","cvss":6.3,"epss":0.0043,"slug":"cve-2026-8754-astrbotdevs-astrbot-path-traversal-in-file-upload-handler","title":"AstrBotDevs AstrBot path traversal in file upload handler","severity":"medium","exploited":false,"published_at":"2026-05-17T13:16:46.107+00:00","url":"https://junglewise.ai/threats/cve-2026-8754-astrbotdevs-astrbot-path-traversal-in-file-upload-handler"},{"cve":"CVE-2026-10212","cvss":6.3,"epss":0.0021,"slug":"cve-2026-10212-astrbotdevs-astrbot-authorization-bypass-via-delimiter-injection","title":"AstrBotDevs AstrBot authorization bypass via delimiter injection in session_id","severity":"medium","exploited":false,"published_at":"2026-06-01T03:16:23.837+00:00","url":"https://junglewise.ai/threats/cve-2026-10212-astrbotdevs-astrbot-authorization-bypass-via-delimiter-injection"},{"cve":"CVE-2026-17530","cvss":6.3,"slug":"cve-2026-17530-astrbotdevs-astrbot-incorrect-authorization-in-subagent-tool","title":"AstrBotDevs AstrBot incorrect authorization in Subagent tool handoff","severity":"medium","exploited":false,"published_at":"2026-07-27T16:17:04.49+00:00","url":"https://junglewise.ai/threats/cve-2026-17530-astrbotdevs-astrbot-incorrect-authorization-in-subagent-tool"},{"cve":"CVE-2026-17529","cvss":6.3,"slug":"cve-2026-17529-astrbotdevs-astrbot-incorrect-authorization-in-astr-main-agent-py","title":"AstrBotDevs AstrBot incorrect authorization in astr_main_agent.py","severity":"medium","exploited":false,"published_at":"2026-07-27T16:17:04.31+00:00","url":"https://junglewise.ai/threats/cve-2026-17529-astrbotdevs-astrbot-incorrect-authorization-in-astr-main-agent-py"},{"cve":"CVE-2026-16076","cvss":6.3,"slug":"cve-2026-16076-astrbotdevs-astrbot-authentication-bypass-via-spoofing-in-openapi","title":"AstrBotDevs AstrBot authentication bypass via spoofing in OpenAPI","severity":"medium","exploited":false,"published_at":"2026-07-18T06:16:35.203+00:00","url":"https://junglewise.ai/threats/cve-2026-16076-astrbotdevs-astrbot-authentication-bypass-via-spoofing-in-openapi"},{"cve":"CVE-2026-16074","cvss":6.3,"slug":"cve-2026-16074-astrbotdevs-astrbot-ssrf-in-plugin-update-handler","title":"AstrBotDevs AstrBot SSRF in Plugin Update Handler","severity":"medium","exploited":false,"published_at":"2026-07-17T21:17:06.087+00:00","url":"https://junglewise.ai/threats/cve-2026-16074-astrbotdevs-astrbot-ssrf-in-plugin-update-handler"},{"cve":"CVE-2026-15501","cvss":6.3,"slug":"cve-2026-15501-astrbotdevs-astrbot-ssrf-in-mcp-test-endpoint","title":"AstrBotDevs AstrBot SSRF in MCP Test Endpoint","severity":"medium","exploited":false,"published_at":"2026-07-12T13:16:36.633+00:00","url":"https://junglewise.ai/threats/cve-2026-15501-astrbotdevs-astrbot-ssrf-in-mcp-test-endpoint"},{"cve":"CVE-2026-15500","cvss":6.3,"slug":"cve-2026-15500-astrbotdevs-astrbot-ssrf-in-market-list-endpoint","title":"AstrBotDevs AstrBot SSRF in market_list endpoint","severity":"medium","exploited":false,"published_at":"2026-07-12T12:16:44.413+00:00","url":"https://junglewise.ai/threats/cve-2026-15500-astrbotdevs-astrbot-ssrf-in-market-list-endpoint"},{"cve":"CVE-2026-15499","cvss":6.3,"slug":"cve-2026-15499-astrbotdevs-astrbot-improper-authorization-in-scheduled-task","title":"AstrBotDevs AstrBot improper authorization in Scheduled Task Handler","severity":"medium","exploited":false,"published_at":"2026-07-12T12:16:44.257+00:00","url":"https://junglewise.ai/threats/cve-2026-15499-astrbotdevs-astrbot-improper-authorization-in-scheduled-task"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}