CVE-2026-17529 | AstrBotDevs AstrBot up to 4.25.5 astr_main_agent.py req.func_tool authorization (Issue 8780)
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5 and classified as critical. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool leads to incorrect authorization.
This vulnerability is listed as CVE-2026-17529. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to install a patch to address this issue.VulDB Recent EntriesRead More