CVE-2026-17530 | AstrBotDevs AstrBot up to 4.25.5 Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization (Issue 8781)

SecurityVulns

A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5 and classified as critical. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization.

This vulnerability is cataloged as CVE-2026-17530. The attack may be launched remotely. Furthermore, there is an exploit available.

A patch should be applied to remediate this issue.VulDB Recent EntriesRead More