PT-2026-3503 · Crawlchat+1 · Crawlchat+1
Egelhaus
·
Published
2026-01-19
·
Updated
2026-02-05
·
CVE-2026-23875
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CrawlChat versions prior to 0.0.8
Description
CrawlChat is a platform that converts technical documentation into intelligent chatbots. Before version 0.0.8, a missing permission check in the Discord bot component allowed users without administrative privileges to add malicious content to the knowledge base. Specifically, the absence of a check for permissions like
MANAGE SERVER or MANAGE MESSAGES allowed regular users to add information to the knowledge base using the jigsaw emoji reaction. This could be exploited to manipulate the bot's responses, potentially redirecting users to malicious sites or sending information to unauthorized individuals. The affected functionality involves adding information to the collection's knowledge base.Recommendations
Update CrawlChat to version 0.0.8 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crawlchat
Discord