Skip to content
This repository was archived by the owner on Nov 7, 2025. It is now read-only.
This repository was archived by the owner on Nov 7, 2025. It is now read-only.

[Security Alert] Your plugin astrbot_plugin_knowledge_base has been delisted #44

@lxfight

Description

@lxfight
  ## AstrBot Plugin Security Alert

  Hello @lxfight,

  Your plugin **astrbot_plugin_knowledge_base** (version v0.5.7) has been automatically delisted from the AstrBot Trusted Marketplace due to a potential security issue found during our automated audit.

  **Reason:**
  ```
  The plugin allows adding a file from a user-provided 'path_or_url'. This functionality is susceptible to Path Traversal vulnerabilities, potentially allowing users to read arbitrary files from the server's file system, and Server-Side Request Forgery (SSRF) by providing internal network URLs.
  ```

  Please review the findings and push an updated version. The new version will be automatically re-audited.

  Thank you,
  The AstrBot Team

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions