PT-2026-70255 · Typebot · Typebot
CVE-2026-47704
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TypeBot versions prior to 3.17.0
Description
An authenticated user with read access to any chatbot can resume a waiting webhook session belonging to a different chatbot. This occurs because the webhook resume handler authorizes the parent chatbot first but resolves the descendant result using only the
resultId variable. By combining an authorized typebotId and blockId with a foreign live resultId, an attacker can inject arbitrary webhook JSON into a suspended session and advance its execution without having access to the target chatbot.Recommendations
Update to version 3.17.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typebot