Exploitation Summary
EIP tracks 2 public exploits for CVE-2025-55449. PoCs published by xhh1h, Marven11.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-55449, targeting AstrBot's JWT authentication bypass and plugin installation mechanism to achieve remote code execution. The exploit forges a JWT token using a hardcoded secret and uploads a malicious plugin to execute arbitrary commands.
Description
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
Exploits (2)
This repository contains a functional exploit for CVE-2025-55449, targeting AstrBot's JWT authentication bypass and plugin installation mechanism to achieve remote code execution. The exploit forges a JWT token using a hardcoded secret and uploads a malicious plugin to execute arbitrary commands.
This repository contains a functional exploit for CVE-2025-55449, which leverages a hardcoded JWT secret in AstrBot <=3.5.17 to achieve RCE via arbitrary plugin upload. The exploit generates a malicious plugin ZIP file and uploads it to the target server, creating a memory shell for command execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L