Impact
A flaw in the AstrBot T2I Feature’s Star.text_to_image/NetworkRenderStrategy.render routine permits injection of malicious client‑side script, resulting in cross‑site scripting. This issue allows an attacker to embed javascript that will execute in the context of the user’s browser when the output image is rendered. The cross‑site scripting flaw could lead to stolen session information or other client‑side data, but those specific consequences are inferred from the XSS nature of the vulnerability.
Affected Systems
The vulnerability affects AstrBotDevs AstrBot versions up to 4.25.2. The impacted component is the T2I Feature, specifically the NetworkRenderStrategy.render function and the Star.text_to_image routine located in astrbot/core/star/base.py.
Risk and Exploitability
The CVSS score of 5.1 classifies the vulnerability as moderate severity. The EPSS score of less than 1% indicates that exploitation is uncommon at present. The issue is not listed in CISA’s KEV catalog. Threat authors can trigger the vulnerability remotely by sending crafted input to the vulnerable endpoint, as the attack vector is described as remote. Mitigation steps are required until a vendor patch is released.
OpenCVE Enrichment