PT-2026-3503 · Crawlchat+1 · Crawlchat+1

Egelhaus

·

Published

2026-01-19

·

Updated

2026-02-05

·

CVE-2026-23875

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CrawlChat versions prior to 0.0.8
Description CrawlChat is a platform that converts technical documentation into intelligent chatbots. Before version 0.0.8, a missing permission check in the Discord bot component allowed users without administrative privileges to add malicious content to the knowledge base. Specifically, the absence of a check for permissions like MANAGE SERVER or MANAGE MESSAGES allowed regular users to add information to the knowledge base using the jigsaw emoji reaction. This could be exploited to manipulate the bot's responses, potentially redirecting users to malicious sites or sending information to unauthorized individuals. The affected functionality involves adding information to the collection's knowledge base.
Recommendations Update CrawlChat to version 0.0.8 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-23875
GHSA-F484-62P4-6W4P

Affected Products

Crawlchat
Discord