Impact
The vulnerability lies in the market_list endpoint of the AstrBot dashboard, specifically within the get_online_plugins function in plugin.py. An attacker can supply a crafted custom_registry argument that causes the AstrBot server to issue HTTP requests to arbitrary URLs. This server‑side request forgery (SSRF) could expose internal services, leak sensitive data, or serve as a foothold for further lateral attacks. The flaw is exploitable remotely and a public exploit has already been released.
Affected Systems
AstrBotDevs AstrBot versions up to 4.25.2 are affected. The weakness resides in the market_list endpoint within the astrbot/dashboard/routes/plugin.py component of the AstrBot application.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate risk, while the EPSS score of less than 1% points to a low, yet non‑zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Because the attack vector is remote, the exploit has been publicly distributed, and the asset may be exposed to untrusted networks, the overall risk to systems remains material.
OpenCVE Enrichment