Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 16 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:langbot:langbot:*:*:*:*:*:*:*:* |
Fri, 06 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langbot
Langbot langbot |
|
| Vendors & Products |
Langbot
Langbot langbot |
Fri, 06 Mar 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied raw HTML using rehypeRaw, which can lead to a cross-site scripting (XSS) vulnerability. This issue has been patched in version 4.8.7. | |
| Title | LangBot has a Cross Site Scripting(XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-06T16:07:49.499Z
Reserved: 2026-02-27T20:57:47.709Z
Link: CVE-2026-28509
Updated: 2026-03-06T15:50:38.552Z
Status : Analyzed
Published: 2026-03-06T05:16:35.590
Modified: 2026-03-16T13:35:12.607
Link: CVE-2026-28509
No data.
OpenCVE Enrichment
Updated: 2026-04-17T12:30:06Z