CVE-2026-54449: LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization bo...
Added to the CISA Known Exploited Vulnerabilities catalog on 20 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.
LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tools/loaders/mcp.py, StdioServerParameters accepts the configur...
Required action: Review and patch if applicable to your AI infrastructure.