Arbitrary File Read Vulnerability in AstrBot Project by DYX217
CVE-2025-57697
6.5MEDIUM
What is CVE-2025-57697?
The AstrBot Project version 3.5.22 contains an arbitrary file read vulnerability within the _encode_image_bs64 function located in entities.py. This function allows attackers to exploit the application's inability to properly validate the legitimacy of user-specified image paths. By crafting malicious URLs, an attacker can gain unauthorized access to sensitive files, leading to potential data exposure and leakage. This vulnerability underscores the importance of secure coding practices, particularly in the context of user inputs and file handling.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
