CVE-2026-90938 debrief: LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 has a critical vulnerability allowing unauthenticated plugin registration via a debug WebSocket server. This issue exposes sensitive information and allows for arbitrary message injection. The vulnerability arises from the server listening on 0.0.0.0:5401 without proper authentication, gated on plugin_debug_key, w [truncated]
CVE-2026-90562 debrief: LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access. This vulnerability allows attackers to exploit weak password recove [truncated]