CVE-2026-8754: Path Traversal in AstrBotDevs AstrBot
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulation of the argument filename results in path traversal. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 4.23.6 is recommended to address this issue. The patch is identified as aaec41e5054569ceaa1113593a34da7568e2d211. You should upgrade the affected component.
AI Analysis
Technical Summary
This vulnerability involves a path traversal flaw in the AstrBotDevs AstrBot product, affecting versions 4.23.0 through 4.23.5. The flaw is located in the post_file function within the File Upload Handler component, where improper validation of the filename parameter allows an attacker to traverse directories on the server remotely. This could potentially lead to unauthorized file access or modification. The vendor has released a patch in version 4.23.6 (commit aaec41e5054569ceaa1113593a34da7568e2d211) to fix this issue. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and low to low impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote attackers to perform path traversal via the filename argument in the file upload handler, potentially accessing or modifying files outside the intended directory. The impact is rated medium with a CVSS score of 5.3, indicating limited but non-negligible risk to confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade AstrBot to version 4.23.6 or later, which contains the official patch (commit aaec41e5054569ceaa1113593a34da7568e2d211) addressing this path traversal vulnerability. No other mitigations are specified or required once the upgrade is applied.
CVE-2026-8754: Path Traversal in AstrBotDevs AstrBot
Description
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulation of the argument filename results in path traversal. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 4.23.6 is recommended to address this issue. The patch is identified as aaec41e5054569ceaa1113593a34da7568e2d211. You should upgrade the affected component.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/astrbotdevs/AstrBotRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a path traversal flaw in the AstrBotDevs AstrBot product, affecting versions 4.23.0 through 4.23.5. The flaw is located in the post_file function within the File Upload Handler component, where improper validation of the filename parameter allows an attacker to traverse directories on the server remotely. This could potentially lead to unauthorized file access or modification. The vendor has released a patch in version 4.23.6 (commit aaec41e5054569ceaa1113593a34da7568e2d211) to fix this issue. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and low to low impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote attackers to perform path traversal via the filename argument in the file upload handler, potentially accessing or modifying files outside the intended directory. The impact is rated medium with a CVSS score of 5.3, indicating limited but non-negligible risk to confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade AstrBot to version 4.23.6 or later, which contains the official patch (commit aaec41e5054569ceaa1113593a34da7568e2d211) addressing this path traversal vulnerability. No other mitigations are specified or required once the upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-05-16T17:33:50.142Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a09b655ec166c07b0c3f736
Added to database: 05/17/2026, 12:36:37 UTC
Last enriched: 05/24/2026, 19:28:30 UTC
Last updated: 07/31/2026, 20:24:39 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.