LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restrict the storage directory of files on the server, it is possible to upload dangerous files to specific system directories. This is fixed in version 4.3.5.
History

Thu, 02 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Description LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restrict the storage directory of files on the server, it is possible to upload dangerous files to specific system directories. This is fixed in version 4.3.5.
Title LangBot has a cross-directory file upload vulnerability, which could lead to system takeover
Weaknesses CWE-23
CWE-434
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-02T19:50:39.752Z

Reserved: 2025-09-22T14:34:03.471Z

Link: CVE-2025-59835

cve-icon Vulnrichment

Updated: 2025-10-02T19:50:34.555Z

cve-icon NVD

Status : Received

Published: 2025-10-02T19:15:31.983

Modified: 2025-10-02T19:15:31.983

Link: CVE-2025-59835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.