astrbot@3.5.12 vulnerabilities

易上手的多平台 LLM 聊天机器人及开发框架

  • latest version

    3.5.13

  • latest non vulnerable version

  • first published

    1 months ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the astrbot package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Relative Path Traversal

    AstrBot is a 易上手的多平台 LLM 聊天机器人及开发框架

    Affected versions of this package are vulnerable to Relative Path Traversal through the /api/chat/get_file endpoint. An attacker can access sensitive information such as API keys and account passwords by manipulating the file path input to traverse to restricted directories.

    How to fix Relative Path Traversal?

    Upgrade AstrBot to version 3.5.13 or higher.

    [,3.5.13)