Description
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
Published: 2026-05-08
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4m32-cjv7-f425 AstrBot is vulnerable to RCE with hard-coded JWT signing keys
History

Tue, 12 May 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:astrbot:astrbot:3.5.15:*:*:*:*:*:*:*

Mon, 11 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Astrbot
Astrbot astrbot
Vendors & Products Astrbot
Astrbot astrbot

Fri, 08 May 2026 23:30:00 +0000

Type Values Removed Values Added
Title Hardcoded Private Key Enables JWT Forgery in AstrBot

Fri, 08 May 2026 21:00:00 +0000

Type Values Removed Values Added
Title Hardcoded Private Key in AstrBot Enables JWT Forgery and Potential Remote Code Execution
Weaknesses CWE-285
CWE-798

Fri, 08 May 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-321
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 08 May 2026 08:00:00 +0000

Type Values Removed Values Added
Title Hardcoded Private Key in AstrBot Enables JWT Forgery and Potential Remote Code Execution
Weaknesses CWE-285
CWE-798

Fri, 08 May 2026 06:30:00 +0000

Type Values Removed Values Added
Description AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-08T17:52:44.644Z

Reserved: 2025-08-13T00:00:00.000Z

Link: CVE-2025-55449

cve-icon Vulnrichment

Updated: 2026-05-08T17:52:40.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-08T07:16:28.047

Modified: 2026-05-12T13:49:53.330

Link: CVE-2025-55449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T16:11:35Z

Weaknesses