Description

LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restrict the storage directory of files on the server, it is possible to upload dangerous files to specific system directories. This is fixed in version 4.3.5.

INFO

Published Date :

2025-10-02T18:59:42.808Z

Last Modified :

2025-10-02T19:50:39.752Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59835 vulnerability.

Vendors Products
Langbot
  • Langbot
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability