{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-90938/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:langbot:langbot_plugin:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-90938"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["langbot_plugin (\u003c= 0.4.17)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","web-application","cve-2026-90938"],"_cs_type":"advisory","_cs_vendors":["LangBot"],"content_html":"\u003cp\u003eThe LangBot plugin runtime, specifically the \u003ccode\u003elangbot_plugin\u003c/code\u003e Python package versions 0.4.17 and earlier, contains a critical vulnerability regarding its debug WebSocket server. The server, accessible at \u003ccode\u003e/plugin/ws\u003c/code\u003e on port 5401, is bound to 0.0.0.0 by default. Authentication for this endpoint relies on a \u003ccode\u003eplugin_debug_key\u003c/code\u003e configuration variable; however, the software defaults this key to an empty string. Because the upstream repository, Docker images, and \u003ccode\u003edocker-compose\u003c/code\u003e configurations fail to set or enforce this key, the authentication check is bypassed entirely.\u003c/p\u003e\n\u003cp\u003eThis allows any remote attacker with network reach to port 5401 to register arbitrary \u0026quot;debug plugins.\u0026quot; Once registered, the attacker's plugin is granted full access to the event broadcast stream, which contains plaintext IM messages, user IDs, and metadata from all conversations. Furthermore, the attacker can leverage the plugin runtime to invoke LLM models, read knowledge-base contents, and register malicious tools into the message pipeline. Additionally, an attacker can cause a persistent denial-of-service by registering a plugin with \u003ccode\u003eprod_mode\u003c/code\u003e set to true, which prevents subsequent legitimate plugin installations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full surveillance of internal IM communications processed by the bot, data exfiltration from knowledge bases, and the injection of unauthorized LLM prompts or replies. By deploying conflicting plugins in \u003ccode\u003eprod_mode\u003c/code\u003e, an attacker can effectively disable legitimate bot functionality, impacting business operations that rely on the LangBot for automated communication or LLM interaction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize network segmentation and access control to mitigate exposure while awaiting an official patch.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement firewall or security group rules to restrict access to port 5401 (TCP) to only trusted administrative IP addresses.\u003c/li\u003e\n\u003cli\u003eAudit existing deployments to determine if the \u003ccode\u003edocker-compose\u003c/code\u003e configuration is exposing port 5401 to the internet or untrusted subnets.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unauthorized WebSocket connections to \u003ccode\u003e/plugin/ws\u003c/code\u003e if application-level logging is available for the LangBot runtime.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T13:34:29Z","date_published":"2026-09-14T13:34:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-langbot-plugin-rce/","summary":"The LangBot langbot_plugin (\u003c= 0.4.17) exposes an unauthenticated debug WebSocket server on port 5401, allowing remote attackers to intercept chat traffic, inject malicious LLM tools, and trigger persistent denial-of-service via plugin registration conflicts.","title":"Unauthenticated Remote Access and Plugin Injection in LangBot langbot_plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-langbot-plugin-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-90938","version":"https://jsonfeed.org/version/1.1"}