CVE-2026-15501 | AstrBotDevs AstrBot up to 4.25.2 MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection mcp_server_config.url server-side request forgery

SecurityVulns

A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.2 and classified as critical. Affected by this issue is the function ToolsRoute.test_mcp_connection of the file astrbot/dashboard/routes/tools.py of the component MCP Test Endpoint. The manipulation of the argument mcp_server_config.url leads to server-side request forgery.

This vulnerability is uniquely identified as CVE-2026-15501. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More