🔐 CVE Alert

CVE-2026-28509

MEDIUM 6.3

LangBot has a Cross Site Scripting(XSS) Vulnerability

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied raw HTML using rehypeRaw, which can lead to a cross-site scripting (XSS) vulnerability. This issue has been patched in version 4.8.7.

CWE CWE-79
Vendor langbot-app
Product langbot
Published Mar 6, 2026
Last Updated Mar 6, 2026
Stay Ahead of the Next One

Get instant alerts for langbot-app langbot

Be the first to know when new medium vulnerabilities affecting langbot-app langbot are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

langbot-app / LangBot
< 4.8.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/langbot-app/LangBot/security/advisories/GHSA-w8gq-g4pc-xh3h github.com: https://github.com/langbot-app/LangBot/commit/614621ab7b84fe50da3c6137705cde5a99429866