PatchSiren

langbot-app CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH langbot-app CVE published 2026-09-14

CVE-2026-90938

CVE-2026-90938 debrief: LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 has a critical vulnerability allowing unauthenticated plugin registration via a debug WebSocket server. This issue exposes sensitive information and allows for arbitrary message injection. The vulnerability arises from the server listening on 0.0.0.0:5401 without proper authentication, gated on plugin_debug_key, w [truncated]

CRITICAL langbot-app CVE published 2026-09-13

CVE-2026-90562

CVE-2026-90562 debrief: LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access. This vulnerability allows attackers to exploit weak password recove [truncated]