CVE-2026-17530

Source
https://cve.org/CVERecord?id=CVE-2026-17530
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17530.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17530
Published
2026-07-27T15:45:10.355Z
Modified
2026-07-29T03:46:05.373113371Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization
Details

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function buildhandofftoolset of the file AstrBot/astrbot/core/astragenttoolexec.py of the component Subagent. The manipulation results in incorrect authorization. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as d23011262e8e75e1ec41b0f1f0091493a022327e. A patch should be applied to remediate this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17530.json",
    "cwe_ids": [
        "CWE-285",
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/astrbotdevs/astrbot

Affected ranges

Type
GIT
Repo
https://github.com/astrbotdevs/astrbot
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "4.25.0"
        },
        {
            "last_affected": "4.25.0"
        },
        {
            "introduced": "4.25.1"
        },
        {
            "last_affected": "4.25.1"
        },
        {
            "introduced": "4.25.2"
        },
        {
            "last_affected": "4.25.2"
        },
        {
            "introduced": "4.25.3"
        },
        {
            "last_affected": "4.25.3"
        },
        {
            "introduced": "4.25.4"
        },
        {
            "last_affected": "4.25.4"
        },
        {
            "introduced": "4.25.5"
        },
        {
            "last_affected": "4.25.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.25.0
4.25.1
4.25.2
4.25.3
4.25.4
4.25.5
v4.*
v4.25.0
v4.25.1
v4.25.2
v4.25.3
v4.25.4
v4.25.5
v4.26.0-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17530.json"