CVE-2026-6119Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Disclosures: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-12: 4Technical Details · 2026-04-12: 304-12
Signal classification2 categories
Disclosure
375.0%
Disclosures
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6119 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6119 #CVE-2026-6119 #CVE #Medium #CyberSecurity #InfoSec https://t.co/C6Zfb8nTF2

    Post summary

    The tweet announces CVE‑2026‑6119 with a medium severity rating and links to the NVD entry, but provides no further technical, exploit, or mitigation details.

    0000029
    125 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6119 A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation … https://www.cve.org/CVERecord?id=CVE-2026-6119 ----- Traducción: CVE-2026-6119 Se … http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-6119) affecting AstrBot (up to version 4.22.1) is announced, pinpointing a flaw in the post_data.get function of the API Endpoint, but no exploit details, patches, or active exploitation are provided.

    0000033
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6119 A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get of the component API Endpoint. Such manipulation … https://www.cve.org/CVERecord?id=CVE-2026-6119

    Post summary

    The post announces CVE‑2026‑6119, detailing the affected function and version, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000376
    57.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosures

    CVE-2026-6119 Server-Side Request Forgery in AstrBotDevs AstrBot Up to 4.22.1 API Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6119

    Post summary

    The text discloses CVE-2026-6119, an SSRF vulnerability affecting AstrBotDevs AstrBot up to v4.22.1, but provides no PoC, exploit, or patch information.

    0000046
    4.0K followersView on X

Explore more