CVE-2025-55449 affects AstrBot 3.5.15. The product uses a hardcoded private key, specifically the string "Advanced_System_for_Text_Response_and_Bot_Operations_Tool", to sign JSON Web Tokens (JWTs). Embedding a fixed secret or private signing key in the application means the credential is not unique per deployment and can be recovered or reused by an attacker. If the application relies on this key to establish the authenticity or integrity of JWT-based authentication or authorization data, an attacker can generate validly signed tokens.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept exploit for CVE-2025-55449, a critical RCE vulnerability in AstrBot. The exploit consists of a main script (main.py) that forges a JWT token using a hardcoded secret, packages a malicious plugin (helloworld) as a ZIP, and uploads it to the target's /api/plugin/install-upload endpoint. The plugin, when installed, injects a /cmd endpoint into the AstrBot web application, allowing the attacker to execute arbitrary shell commands via HTTP requests. The repository includes a sample plugin directory (helloworld/) with the malicious code, plugin metadata, and supporting files. The exploit can target a single URL or multiple targets listed in ip.txt. The main attack vector is network-based, exploiting weak authentication and plugin validation in AstrBot's API. The exploit is operational, providing a working payload and clear instructions for use.
This repository contains an exploit for AstrBot versions <= 3.5.17, which hardcodes a JWT secret in its source code. The exploit leverages this secret to generate a valid JWT token, allowing unauthorized upload of a malicious plugin via the '/api/plugin/install-upload' endpoint. The main exploit script (main.py) creates a zip file containing a plugin (payload-zip-main), which, when installed, registers a new HTTP endpoint '/test_memshell'. This endpoint acts as a webshell, executing arbitrary OS commands provided via the 'cmd' query parameter. The repository is structured with a main exploit script, a payload directory containing the plugin code and metadata, and supporting files for development. The exploit demonstrates a full attack chain: authentication bypass via hardcoded secret, plugin upload, and remote code execution via a webshell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.