Impact
LangBot versions earlier than 4.10.11 can generate password recovery keys with only 24 bits of entropy, which is far below the level required. Knowing the administrator e‑mail address, attackers can exhaust the limited keyspace by flooding the unauthenticated reset‑password endpoint, thereby bypassing authentication and gaining administrative access for the application.
Affected Systems
The vulnerability affects the LangBot application produced by langbot-app. All installations running any version earlier than 4.10.11 are potentially vulnerable, as the weak key generation is implemented in the core recovery key module and the reset endpoint lacks any form of rate limiting. Users of the latest releases to have a patched implementation.
Risk and Exploitability
The CVSS score of 9.2 classifies this flaw as critical, indicating that exploitation could lead to total compromise of the system. The EPSS score is approximately 0.00424 (~0.42%), indicating a very low overall likelihood of exploitation but does not negate the risk in targeted scenarios. The lack of rate limiting and the extremely small keyspace make this exploit highly likely in practice, even though it is not yet listed in KEV. The attack vector is inferred to be remote, leveraging the unauthenticated reset‑password API and exhaustive key guessing.
OpenCVE Enrichment