CVE-2026-6118General

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulation of the argument command causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-12); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-12: 4Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-14: 1Technical Details · 2026-04-12: 3Technical Details · 2026-04-14: 104-1204-14
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-124
Disclosure1General3
2026-04-141
Disclosure1
Full discourse5 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-6118 - high 🚨 AstrBot <= 4.22.1 - Command Injection > AstrBot versions up to and including 4.22.1 contain a command injection vulnerability... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-6118 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2026-6118, a command‑injection vulnerability affecting AstrBot versions up to 4.22.1, and links to a CVE library for additional details.

    00022187
    930 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6118 A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the compone… https://www.cve.org/CVERecord?id=CVE-2026-6118

    Post summary

    The message reports a new CVE in AstrBot, identifying the affected function and file, but offers no evidence of exploitation, PoC, or patch information.

    00010483
    57.1K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-6118 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6118 #CVE-2026-6118 #CVE #Medium #CyberSecurity #InfoSec https://t.co/7Gwc1J9U5w

    Post summary

    The tweet is a brief announcement of CVE-2026-6118 with a Medium severity rating and no additional technical, exploit, or mitigation information.

    0000030
    125 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6118 A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the compone… https://www.cve.org/CVERecord?id=CVE-2026-6118 ----- Traducción: CVE-2026-6118 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑6118, identifies affected code and versions, but lacks details on PoC, exploits, or patches.

    0000034
    71 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6118 Remote Command Injection in AstrBotDevs AstrBot Up to 4.22.1 MCP Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6118

    Post summary

    A new Remote Command Injection vulnerability (CVE-2026-6118) affecting AstrBotDevs AstrBot up to version 4.22.1 MCP Endpoint has been disclosed, with a link to the vulnerability details page.

    0000052
    4.0K followersView on X

Explore more