CVE-2025-48957 - CVE House
Back to Database
Status published High CVE-2025-48957

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

Vulnerability Description

AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has been addressed in Pull Request #1676 and is included in version 3.5.13. As a workaround, users can edit the `cmd_config.json` file to disable the dashboard feature as a temporary workaround. However, it is strongly recommended to upgrade to version v3.5.13 or later to fully resolve this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48957

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

AstrBotDevs

View all reports →

Affected Software

AstrBot
Vulnerable Versions:
>= 3.4.4, < 3.5.13

Timeline

Official Publish: June 2nd, 2025
Last Modified: June 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)