Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-48957

22
FAUCET Score

CVE-2025-48957 describes a path traversal vulnerability in AstrBot versions 3.4.4 through 3.5.12, a large language model chatbot and development framework. This flaw, rated 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), allows unauthenticated attackers to access sensitive information like API keys and account passwords due to its network-based attack vector and low complexity. While there is no evidence of active exploitation, public exploit code, or significant community discussion, immediate upgrade to version 3.5.13 or later is strongly recommended, with disabling the dashboard feature as a temporary workaround.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.4.4, < 3.5.13CPE matchmatch criteria
cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 23rd percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: astrbotFixed in: 3.5.13

Vendor Advisories (1)

pipGHSA-cq37-g2qp-3c2phigh

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

Jun 4, 2025

References

vicarius.io / vsociety/posts/cve-2025-48957-detect-astrbot-dashboard-vulnerability
ExploitThird Party Advisory
vicarius.io / vsociety/posts/cve-2025-48957-mitigate-astrbot-dashboard-vulnerability
MitigationThird Party Advisory
github.com / AstrBotDevs/AstrBot/commit/cceadf222c46813c7f41115b40d371e7eb91e492
Patch
github.com / AstrBotDevs/AstrBot/issues/1675
ExploitIssue Tracking
github.com / AstrBotDevs/AstrBot/pull/1676
ExploitIssue TrackingPatch
github.com / AstrBotDevs/AstrBot/security/advisories/GHSA-cq37-g2qp-3c2p
ExploitVendor Advisory