Skip to main content

CVE-2026-90562: Insufficient Entropy in langbot-app LangBot

0
Critical
VulnerabilityCVE-2026-90562cvecve-2026-90562
Published: 09/13/2026 (09/13/2026, 10:45:36 UTC)
Source: CVE Database V5
Vendor/Project: langbot-app
Product: LangBot

Description

LangBot versions from 4.0.8.1 up to but not including 4.10.11 have a vulnerability where password recovery keys are generated with only 24 bits of entropy and the reset-password endpoint lacks rate limiting. This allows remote attackers who know the administrator email to exhaust the keyspace via concurrent requests and reset the admin password, potentially gaining account access.

CVSS v4.0

Score 9.2critical

Attack Vector
Network
Attack Complexity
High
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

langbot-app

LangBot

Affected versions
>=4.0.8.1 <4.10.11
GitHub Actionsmore threats →ai
langbot-app/LangBot
pkg:github/langbot-app/LangBot
Affected versions
>=4.0.8.1 <4.10.11

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 11:17:33 UTC

Technical Analysis

CVE-2026-90562 affects LangBot before version 4.10.11. The vulnerability arises because password recovery keys are generated with insufficient entropy (24 bits), making them guessable through brute force. Additionally, the unauthenticated reset-password endpoint does not implement rate limiting, enabling attackers to rapidly attempt many keys. An attacker who knows the administrator's email can exploit this to exhaust the keyspace and reset the administrator password, thereby gaining unauthorized access.

Potential Impact

An attacker can gain unauthorized administrative access by exploiting the weak entropy in password recovery keys combined with the lack of rate limiting on the reset-password endpoint. This compromises account security and potentially the entire system managed by the administrator.

Mitigation Recommendations

A fix is available in LangBot version 4.10.11 and later. Users should upgrade to version 4.10.11 or newer to address this vulnerability. Until then, implementing rate limiting on the reset-password endpoint and increasing entropy for recovery keys can reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-12T11:13:43.327Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aa682ac55bf5e2cf583e18a

Added to database: 09/13/2026, 11:02:04 UTC

Last enriched: 09/13/2026, 11:17:33 UTC

Last updated: 09/13/2026, 15:28:01 UTC

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses