CVE-2026-28509: Langbot

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied raw HTML using rehypeRaw, which can lead to a cross-site scripting (XSS) vulnerability. This issue has been patched in version 4.8.7.

Affected products

  • Langbot Langbot: before 4.8.7 (fixed in 4.8.7)

Published 2026-03-06. Last modified 2026-06-17.