<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:langbot:langbot:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alangbotlangbot/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 13 Sep 2026 11:25:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alangbotlangbot/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insufficient Entropy and Lack of Rate Limiting in LangBot Password Recovery</title><link>https://feed.craftedsignal.io/briefs/2026-09-langbot-password-reset/</link><pubDate>Sun, 13 Sep 2026 11:25:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-langbot-password-reset/</guid><description>LangBot versions prior to 4.10.11 are vulnerable to account takeover via a predictable password reset process due to insufficient entropy in recovery keys and a lack of rate limiting on the reset endpoint.</description><content:encoded>&lt;p>LangBot versions prior to 4.10.11 contain a security vulnerability in the password recovery mechanism that allows remote, unauthenticated attackers to hijack administrator accounts. The application generates password reset tokens with only 24 bits of entropy, which results in a significantly small keyspace. Furthermore, the application fails to implement rate limiting on the unauthenticated reset-password endpoint, enabling attackers to systematically brute-force the recovery keys. By targeting a known administrator email address, an attacker can launch concurrent requests to the reset-password endpoint, exhaust the 24-bit keyspace in a short time, and successfully reset the password to gain unauthorized access to the LangBot environment. This vulnerability poses a critical risk to organizations relying on LangBot for sensitive operations, as it bypasses standard authentication controls without requiring prior valid credentials.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>