MCPA-2026-0037
highrce-vectorsCVSS 8.8
LangBot authenticated RCE via STDIO MCP server configuration (CVE-2026-54449)
LangBot (PyPI: langbot) through 4.10.5: any authenticated user can achieve arbitrary command execution on the LangBot server by adding an 'STDIO' MCP server with an arbitrary command in the MCP Server Configuration — the command is passed to StdioServerParameters and executed on the host. No fixed release was available at publication.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | langbot | >= 0, <= 4.10.5 |
Identifiers
CVE-2026-54449GHSA-3pvh-63gf-j9mwCWE-77
References
- advisory https://github.com/langbot-app/LangBot/security/advisories/GHSA-3pvh-63gf-j9mw
- web https://github.com/advisories/GHSA-3pvh-63gf-j9mw
Timeline
- Published: 2026-07-15