What is CVE-2026-17530?
A security flaw has been discovered in AstrBotDevs AstrBot up to version 4.25.5, affecting the `_build_handoff_toolset` function in `AstrBot/astrbot/core/astr_agent_tool_exec.py` of the Subagent component, leading to incorrect authorization. This could allow attackers to perform unauthorized actions, and users are advised to update to the latest version immediately.
Azərbaycanca: AstrBotDevs-in AstrBot proqramının 4.25.5-ə qədər versiyalarında Subagent komponentinin `AstrBot/astrbot/core/astr_agent_tool_exec.py` faylındakı `_build_handoff_toolset` funksiyasında yanlış avtorizasiyaya səbəb olan təhlükəsizlik zəifliyi aşkar edilib. Bu, təcavüzkara icazəsiz əməliyyatlar aparmağa imkan verə bilər. Təsirə məruz qalan istifadəçilərə dərhal proqramı son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: AstrBotDevs
FAQ2
Which versions of AstrBot are affected by CVE-2026-17530?
This security flaw affects versions of AstrBotDevs' AstrBot up to 4.25.5.
In which component of AstrBot is CVE-2026-17530 located?
The flaw is located in the `_build_handoff_toolset` function in `AstrBot/astrbot/core/astr_agent_tool_exec.py` of the Subagent component.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.