Known Vulnerabilities for LangBot by Langbot-app
Listed below are 3 of the newest known vulnerabilities associated with "LangBot" by "Langbot-app".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90938 json | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90562 json | LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unau... | Not Provided | 2026-09-13 | 2026-09-13 |
| CVE-2026-54449 json | LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or chang... | Not Provided | 2026-08-20 | 2026-08-21 |