<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 12:40:06 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-90938 — LangBot through 0.4.17 Unauthenticated Plugin Registration via WebSocket</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-90938</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langbot-app LangBot&lt;/p&gt;
&lt;p&gt;LangBot&amp;#39;s plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by the upstream repository, Docker image, or docker-compose (which additionally publishes port 5401 to the host); the key check is therefore skipped entirely. Any remote attacker able to reach the port can register an arbitrary &amp;#34;debug plugin&amp;#34; without credentials. Because events are broadcast to all initialized plugins without filtering, the attacker&amp;#39;s plugin receives the full context of every IM message event (including private chats, message chains, and user/sender IDs in plaintext) and can inject forged replies, send messages as any configured bot, enumerate bot UUIDs, invoke configured LLM models, read knowledge-base contents, and register malicious tools that feed every user&amp;#39;s LLM pipeline. Registering with &amp;#34;prod_mode&amp;#34;: true causes later legitimate installations of a plugin with the same author/name to be rejected, resulting in persistent denial of service. No patched version was available at the time of publication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langbot-app LangBot&lt;/p&gt;
&lt;p&gt;LangBot&amp;#39;s plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by the upstream repository, Docker image, or docker-compose (which additionally publishes port 5401 to the host); the key check is therefore skipped entirely. Any remote attacker able to reach the port can register an arbitrary &amp;#34;debug plugin&amp;#34; without credentials. Because events are broadcast to all initialized plugins without filtering, the attacker&amp;#39;s plugin receives the full context of every IM message event (including private chats, message chains, and user/sender IDs in plaintext) and can inject forged replies, send messages as any configured bot, enumerate bot UUIDs, invoke configured LLM models, read knowledge-base contents, and register malicious tools that feed every user&amp;#39;s LLM pipeline. Registering with &amp;#34;prod_mode&amp;#34;: true causes later legitimate installations of a plugin with the same author/name to be rejected, resulting in persistent denial of service. No patched version was available at the time of publication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-90938</guid>
    </item>
  </channel>
</rss>
