AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
References
| Link | Resource |
|---|---|
| https://github.com/AstrBotDevs/AstrBot | Product |
| https://github.com/Marven11/CVE-2025-55449-AstrBot-RCE | Exploit Third Party Advisory |
Configurations
History
12 May 2026, 13:49
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:astrbot:astrbot:3.5.15:*:*:*:*:*:*:* | |
| References | () https://github.com/AstrBotDevs/AstrBot - Product | |
| References | () https://github.com/Marven11/CVE-2025-55449-AstrBot-RCE - Exploit, Third Party Advisory | |
| First Time |
Astrbot
Astrbot astrbot |
08 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-321 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
08 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 07:16
Updated : 2026-05-12 13:49
NVD link : CVE-2025-55449
Mitre link : CVE-2025-55449
CVE.ORG link : CVE-2025-55449
JSON object : View
Products Affected
astrbot
- astrbot
CWE
CWE-321
Use of Hard-coded Cryptographic Key
