Junglewise Threat Intelligence

CVE-2026-5557: Badlogic pi-mono authentication bypass in pi-mom Slack Bot

CVE-2026-5557 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Technologies: Badlogic Pi-Mono. Vendors: Badlogic.

Executive brief

A security flaw exists in the pi-mom Slack Bot component of the badlogic pi-mono library. This vulnerability allows an attacker to bypass authentication mechanisms by using an alternate communication channel. If exploited, an unauthorized user could gain access to bot functions or data they are not permitted to see, potentially disrupting Slack-based operations or leaking internal information.

Technical details

An authentication bypass vulnerability (CWE-288/CWE-287) exists in the pi-mom Slack Bot component of badlogic pi-mono up to version 0.58.4. The issue is located in the processing logic within 'packages/mom/src/slack.ts'. A remote attacker with low privileges can exploit this by using an alternate channel to bypass intended authentication requirements. Successful exploitation allows the attacker to perform actions or access data as an authenticated user. A public exploit (PoC) is reportedly available, and the vendor has not yet released a patch or responded to the disclosure.

Affected products

  • badlogic pi-mono up to 0.58.4

Timeline

  • 2026-03-19: disclosed: Initial discovery/issue opened on GitHub
  • 2026-04-05: advisory: CVE published and VulDB entry created

References

Related threats