Executive brief
LangBot is a platform for building chatbots across multiple messaging services. The password recovery mechanism generates weak reset tokens with insufficient randomness (24 bits of entropy) and lacks rate limiting on the unauthenticated password reset endpoint. An attacker who knows an administrator's email address can rapidly attempt all possible recovery keys and gain unauthorized access to the admin account, compromising the entire bot platform.
Technical details
LangBot's password recovery mechanism suffers from two critical flaws: it generates password reset tokens using only 24 bits of entropy (approximately 16 million possible values) and implements no rate limiting on the unauthenticated password reset endpoint. An attacker can exploit this by obtaining the target administrator's email address (often public) and then performing a brute-force attack against the reset endpoint with concurrent requests. Since the keyspace is computationally small and undefended by rate limiting, all possibilities can be exhausted in seconds or minutes, allowing the attacker to complete a password reset and gain full administrative access. The vulnerability is fixed in LangBot version 4.10.11 or later.
Affected products
- LangBot LangBot before 4.10.11
Timeline
- 2026-09-13: disclosed