Skip to content

MCPA-2026-0037

highrce-vectorsCVSS 8.8

LangBot authenticated RCE via STDIO MCP server configuration (CVE-2026-54449)

LangBot (PyPI: langbot) through 4.10.5: any authenticated user can achieve arbitrary command execution on the LangBot server by adding an 'STDIO' MCP server with an arbitrary command in the MCP Server Configuration — the command is passed to StdioServerParameters and executed on the host. No fixed release was available at publication.

Affected packages

EcosystemPackageAffected versions
pypilangbot
>= 0, <= 4.10.5

Identifiers

CVE-2026-54449GHSA-3pvh-63gf-j9mwCWE-77

References

Timeline

  • Published: 2026-07-15

← All advisories