Unauthenticated Plugin Registration Vulnerability in LangBot by LangBot Developers
CVE-2026-90938

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90938?

The LangBot plugin runtime through version 0.4.17 is vulnerable due to its debug WebSocket server being exposed on 0.0.0.0:5401 without adequate authentication controls. The default setting for the authentication key is an empty string, allowing remote attackers to register arbitrary 'debug plugins'. This exploit allows attackers to intercept all messages, including private communications, and manipulate interactions by injecting false replies and controlling bot actions. Furthermore, the improper registration mechanism may lead to service denial for legitimate installations. No patched version was released at the time of reporting.

Affected Version(s)

LangBot 0 <= 0.4.17

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

T4rnRookie
.