PT-2026-70257 · Typebot · Typebot

CVE-2026-48495

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.17.0
Description The Google Sheets OAuth callback decodes a base64-encoded JSON state parameter and trusts the embedded workspaceId, typebotId, blockId, and redirectUrl without cryptographic integrity protection or authorization checks. Although the callback route is authenticated, it fails to verify if the authenticated user has write access to the target workspace or Typebot before creating credentials or updating Typebot groups. An authenticated user with a valid Google OAuth code can manipulate the state value to create Google Sheets credentials in a different workspace and, provided the target IDs are known, attach those credentials to a block in another Typebot.
Recommendations Update to version 3.17.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48495
GHSA-W789-9GXQ-2XCJ

Affected Products

Typebot