References https://www.secrss.com/articles/85082 https://avd.aliyun.com/detail?id=AVD-2025-55449 https://zhuanlan.zhihu.com/p/1974146792665927764 https://www.gm7.org/archives/1196 https://www.secevery.com/toBugInfo?id=1990304487194763265 https://github.com/Marven11/CVE-2025-55449-AstrBot-RCE https://advisories.gitlab.com/pypi/astrbot/CVE-2025-55449/ https://www.gm7.org/archives/1947 https://osv.dev/vulnerability/GHSA-4m32-cjv7-f425 https://adg.csdn.net/69523fe85b9f5f31781b444b.html
Related VulnerabilitiesPoCCVE-2026-6118: AstrBot <= 4.22.1 - Command InjectionPoCastrbot-default-login: AstrBot - Default LoginAstrBot 存在上传插件RCE漏洞(CVE-2025-55449)AstrBot 存在未授权访问漏洞AstrBot /api/plugin/install-upload 命令执行漏洞(CVE-2025-55449)AstrBot /api/auth/login 默认口令漏洞AstrBot /api/chat/get_file 目录遍历漏洞 (CVE-2025-48957)AstrBot get_file接口存在任意文件读取(CVE-2025-48957)(CVE-2025-48957) AstrBot路径遍历漏洞导致敏感信息泄露