Description
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.
Published: 2026-07-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in AstrBot’s Subagent component within the _build_handoff_toolset function of astr_agent_tool_exec.py. By manipulating input, an attacker can cause the function to grant improper authorization, effectively bypassing expected access controls. This flaw leads to unauthorized privilege escalation and potential lateral movement within systems that rely on AstrBot for command execution or automation.

Affected Systems

Affected versions are AstrBot up to 4.25.5 by AstrBotDevs. The product family AstrBot, as identified by the Astrbot CPE string, is impacted across all platforms where Subagent is deployed. The patch commit d23011262e8e75e1ec41b0f1f0091493a022327e resolves the issue.

Risk and Exploitability

The CVSS v3 score of 5.3 indicates a moderate severity, and the EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack path is remote, and exploitation has been publicly released, suggesting that the risk to exposed installations is non‑negligible. An attacker would need the ability to supply crafted input to the toolset builder, which may be possible via exposed interfaces or network connections used by the subagent, making the vulnerability fairly exploitable in uncontrolled environments.

Generated by OpenCVE AI on August 4, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AstrBot to version 4.25.6 or later by applying patch commit d23011262e8e75e1ec41b0f1f0091493a022327e.
  • If immediate upgrade is not feasible, disable the Subagent component or restrict access to _build_handoff_toolset to trusted users only.
  • Review and strengthen authorization checks and role‑based access controls for all AstrBot automatic tool execution modules.
  • Restart AstrBot services so changes are enforced.

Generated by OpenCVE AI on August 4, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.
Title AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
First Time appeared Astrbot
Astrbot astrbot
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:*
Vendors & Products Astrbot
Astrbot astrbot
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-27T18:19:50.134Z

Reserved: 2026-07-27T08:45:52.537Z

Link: CVE-2026-17530

cve-icon Vulnrichment

Updated: 2026-07-27T18:19:43.321Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T16:17:04.490

Modified: 2026-07-27T20:25:13.817

Link: CVE-2026-17530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:00:03Z

Weaknesses