CVE-2025-57698: Astrbot
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses the filename to assign to file_path without checking the validity of the filename. The variable file_path is then passed as a parameter to the function `file.save`, so that the file in the request body can be saved to any location in the file system through directory traversal.
Affected products
- Astrbot Astrbot: version 3.5.22 only
Published 2025-11-07. Last modified 2026-06-17.