What is CVE-2026-17529?
A critical incorrect authorization vulnerability exists in AstrBotDevs AstrBot up to version 4.25.5, stemming from manipulation of the `req.func_tool` argument in `astrbot/core/astr_main_agent.py`. This flaw allows remote attacks and has a publicly available exploit, putting affected systems at high risk.
Azərbaycanca: Bu kritik zəiflik AstrBot-un 4.25.5-ə qədər versiyalarında `astr_main_agent.py` faylındakı `req.func_tool` arqumentinin manipulyasiyası nəticəsində səhv avtorizasiyaya səbəb olur. Uzaqdan istismar mümkündür və zəiflik üçün açıq istismar kodu mövcuddur, bu da təsirlənmiş sistemləri yüksək risk altına qoyur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: AstrBotDevs
FAQ2
Which versions of AstrBot are affected by CVE-2026-17529?
This vulnerability affects all versions of AstrBot up to version 4.25.5.
Is there a publicly available exploit for CVE-2026-17529?
Yes, a publicly available exploit exists for this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.