No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 12 Apr 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | AstrBotDevs AstrBot API Endpoint post_data.get server-side request forgery | |
| First Time appeared |
Astrbot
Astrbot astrbot |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Astrbot
Astrbot astrbot |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-12T05:00:20.093Z
Reserved: 2026-04-11T08:50:24.541Z
Link: CVE-2026-6119
No data.
Status : Received
Published: 2026-04-12T06:16:21.927
Modified: 2026-04-12T06:16:21.927
Link: CVE-2026-6119
No data.
OpenCVE Enrichment
No data.