Unauthenticated Plugin Registration Vulnerability in LangBot by LangBot Developers
CVE-2026-90938
8.8HIGH
What is CVE-2026-90938?
The LangBot plugin runtime through version 0.4.17 is vulnerable due to its debug WebSocket server being exposed on 0.0.0.0:5401 without adequate authentication controls. The default setting for the authentication key is an empty string, allowing remote attackers to register arbitrary 'debug plugins'. This exploit allows attackers to intercept all messages, including private communications, and manipulate interactions by injecting false replies and controlling bot actions. Furthermore, the improper registration mechanism may lead to service denial for legitimate installations. No patched version was released at the time of reporting.
Affected Version(s)
LangBot 0 <= 0.4.17
