Product
LangBot versions prior to 4.10.11 are vulnerable to account takeover via a predictable password reset process due to insufficient entropy in recovery keys and a lack of rate limiting on the reset endpoint.