mediumCVSS 7.3Vulnerability

CVE-2026-7579

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
medium
summary
AstrBot Makes Use of Hard-coded Password
epss_score
0.00288
cvss_score
7.3
ghsa_published
2026-05-01T12:30:25Z
source_url
https://github.com/advisories/GHSA-mq9q-25hm-g4gp
ghsa_updated
2026-05-07T02:55:42Z
ghsa_id
GHSA-mq9q-25hm-g4gp
cve_id
CVE-2026-7579
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.21486

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/AstrBot

AFFECTS (1)

[Software]pip/AstrBot

HAS_WEAKNESS (1)

[Weakness]Use of Hard-coded Password

Explore deeper with Ninja Signal's threat intelligence graph