CVE-2025-55449

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:astrbot:astrbot:3.5.15:*:*:*:*:*:*:*

History

12 May 2026, 13:49

Type Values Removed Values Added
CPE cpe:2.3:a:astrbot:astrbot:3.5.15:*:*:*:*:*:*:*
References () https://github.com/AstrBotDevs/AstrBot - () https://github.com/AstrBotDevs/AstrBot - Product
References () https://github.com/Marven11/CVE-2025-55449-AstrBot-RCE - () https://github.com/Marven11/CVE-2025-55449-AstrBot-RCE - Exploit, Third Party Advisory
First Time Astrbot
Astrbot astrbot

08 May 2026, 18:16

Type Values Removed Values Added
CWE CWE-321
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

08 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 07:16

Updated : 2026-05-12 13:49


NVD link : CVE-2025-55449

Mitre link : CVE-2025-55449

CVE.ORG link : CVE-2025-55449


JSON object : View

Products Affected

astrbot

  • astrbot
CWE
CWE-321

Use of Hard-coded Cryptographic Key