CVE-2026-6984

Source
https://cve.org/CVERecord?id=CVE-2026-6984
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6984.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6984
Aliases
Published
2026-04-25T15:30:24.742Z
Modified
2026-07-15T01:48:55.622729398Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
AstrBotDevs AstrBot Dashboard API t2i.py create_template special elements used in a template engine
Details

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-1336",
        "CWE-791"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6984.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/astrbotdevs/astrbot

Affected ranges

Type
GIT
Repo
https://github.com/astrbotdevs/astrbot
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "4.22.0"
        },
        {
            "last_affected": "4.22.0"
        },
        {
            "introduced": "4.22.1"
        },
        {
            "last_affected": "4.22.1"
        }
    ]
}

Affected versions

4.*
4.22.0
4.22.1
v4.*
v4.22.0
v4.22.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6984.json"