Impact
AstrBotDevs AstrBot’s _normalize_rw_path routine can resolve symbolic links incorrectly. When a crafted path is supplied, the routine follows the link and can read or write files outside the intended workspace. This flaw is identified as CWE‑59 and allows a local attacker to access data that should remain protected. The CVSS score of 4.8 reflects a moderate local impact, focusing on confidentiality and integrity.
Affected Systems
All installations of AstrBotDevs AstrBot version 4.25.5 and earlier are affected. The vulnerability is located in astrbot/core/tools/computer_tools/fs.py and is not present in later releases. No other products or vendors were noted as vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, indicating that exploitation is currently unlikely, but the publicly disclosed exploit remains available. Because the flaw requires local access, compromising the AstrBot service or the account running it would permit the attacker to traverse directories. The defect is not listed in CISA KEV and no vendor patch has been issued, so the primary risk is the potential for local privilege misuse rather than a widespread attack vector.
OpenCVE Enrichment