PT-2025-40417 · Langbot · Langbot
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
LangBot versions 4.1.0 through 4.3.4
Description
LangBot is a global IM bot platform designed for LLMs. Authorized attackers can exploit the
/api/v1/files/documents interface to perform arbitrary file uploads. The interface does not strictly restrict the storage directory of files on the server, allowing the upload of dangerous files to specific system directories. The files parameter within the /api/v1/files/documents endpoint is vulnerable.Recommendations
Update to version 4.3.5 or later.
Exploit
Fix
Relative Path Traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langbot