CVE-2022-21669

CRITICAL

puddingbot < 0.0.6-b933652 - Use of Hard-coded Credentials in main.py

Title source: llm
STIX 2.1

Description

PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the maintainers are planning to update code to reflect this change at a later date.

Scores

CVSS v3 9.1
EPSS 0.0103
EPSS Percentile 59.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
puddingbot_project/puddingbot < 0.0.6-b933652
Published Jan 11, 2022
Tracked Since Feb 18, 2026