Authorization Flaw in AstrBot by AstrBotDevs
CVE-2026-17530
Key Information:
- Vendor
Astrbotdevs
- Status
- Vendor
- CVE Published:
- 27 July 2026
Badges
What is CVE-2026-17530?
A significant security flaw has been identified in the AstrBot application developed by AstrBotDevs. This vulnerability affects the _build_handoff_toolset function in the astr_agent_tool_exec.py file, which is part of the Subagent component. The exploit allows attackers to manipulate the authorization process, potentially leading to unauthorized access. This issue can be exploited remotely, raising concerns for any installations of AstrBot up to version 4.25.5. A patch has been issued (d23011262e8e75e1ec41b0f1f0091493a022327e) to mitigate the risks associated with this vulnerability.
Affected Version(s)
AstrBot 4.25.0
AstrBot 4.25.1
AstrBot 4.25.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
