PT-2026-70219 · Typebot · Typebot

CVE-2026-47702

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.17.0
Description TypeBot stores API tokens, which are bearer credentials used to authenticate against the builder API, as cleartext strings in the database. An attacker with read access to the database can extract these tokens to impersonate any user, bypassing the need for passwords or multi-factor authentication.
Recommendations Update to version 3.17.0.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47702
GHSA-9C96-GCG3-2662

Affected Products

Typebot