VDB
GCVE-110-BRLY-2026-050
GCVE-110-BRLY-2026-050
Advisory Published
BRLY-2026-050 Critical BINARLY REsearch team identified an exposed Slack bot token and Slack app-level token embedded in a container image hosted on Docker Hub. The bot token was verified as valid and belongs to the Toradex Slack workspace. The app-level token was stored in the same configuration file and was also verified as valid.
The bot token provides message-history, file, message-posting, private-conversation, remote-file, and user-information access. The app-level token permits a Slack Socket Mode connection.
References
Browse GCVE Records
556 records in the GCVE database · Updated September 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.