Impact
AstrBotDevs AstrBot contains a flaw in the FutureTaskTool.call function within the scheduled‑task handler module that allows an attacker to manipulate the payload["note"] argument to bypass authentication checks. This improper authorization can enable the creation or modification of scheduled tasks without proper credentials, potentially allowing the execution of arbitrary commands or scripts. The vulnerability is catalogued with a CVSS score of 5.3, indicating a moderate risk of compromise.
Affected Systems
All installations of AstrBotDevs AstrBot through version 4.25.2 are impacted. The issue resides specifically in the scheduled‑task handler component located in the astrbot/core/tools/cron_tools.py file.
Risk and Exploitability
The flaw is remotely exploitable and a public exploit is available. However, the EPSS score is reported as <1%, suggesting current exploitation frequency is very low, and the vulnerability is not listed in the CISA KEV catalog. The moderate CVSS score reflects the potential impact of unauthorized task execution, while the low EPSS indicates a limited immediate threat. Attackers would need to send a crafted payload that alters the "note" field to gain the elevated privileges required to modify scheduled tasks.
OpenCVE Enrichment