Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 12 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulation of the argument command causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | AstrBotDevs AstrBot MCP Endpoint tools.py add_mcp_server command injection | |
| First Time appeared |
Astrbot
Astrbot astrbot |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:astrbot:astrbot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Astrbot
Astrbot astrbot |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-12T04:45:09.857Z
Reserved: 2026-04-11T08:50:21.092Z
Link: CVE-2026-6118
No data.
Status : Received
Published: 2026-04-12T05:16:01.560
Modified: 2026-04-12T05:16:01.560
Link: CVE-2026-6118
No data.
OpenCVE Enrichment
No data.