AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676 and is included in version 3.5.13. As a workaround, users can edit the `cmd_config.json` file to disable the dashboard feature as a temporary workaround. However, it is strongly recommended to upgrade to version v3.5.13 or later to fully resolve this issue.
History

Wed, 25 Jun 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Astrbot
Astrbot astrbot
Weaknesses CWE-22
CPEs cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:*
Vendors & Products Astrbot
Astrbot astrbot
References

Wed, 25 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CPEs cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:*
Vendors & Products Astrbot
Astrbot astrbot
References

Wed, 25 Jun 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Astrbot
Astrbot astrbot
Weaknesses CWE-22
CPEs cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:*
Vendors & Products Astrbot
Astrbot astrbot

Mon, 23 Jun 2025 18:30:00 +0000


Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Jun 2025 11:30:00 +0000

Type Values Removed Values Added
Description AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676 and is included in version 3.5.13. As a workaround, users can edit the `cmd_config.json` file to disable the dashboard feature as a temporary workaround. However, it is strongly recommended to upgrade to version v3.5.13 or later to fully resolve this issue.
Title AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-02T11:16:14.370Z

Updated: 2025-06-23T18:03:57.703Z

Reserved: 2025-05-28T18:49:07.585Z

Link: CVE-2025-48957

cve-icon Vulnrichment

Updated: 2025-06-23T18:03:57.703Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-02T12:15:25.680

Modified: 2025-06-25T17:39:23.137

Link: CVE-2025-48957

cve-icon Redhat

No data.