CVE-2023-39740: Linecorp Onigiriya-Musubee

High severity, CVSS 8.2. EPSS: 0.6% chance of exploitation in the next 30 days.

The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

Affected products

  • Linecorp Onigiriya-Musubee: version 13.6.1 only

Published 2023-10-25. Last modified 2026-06-17.