PT-2026-70793 · Typebot · Typebot
CVE-2026-47705
·
Published
2026-08-11
·
Updated
2026-08-13
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TypeBot versions prior to 3.17.0
Description
The result export functionality fails to sanitize or escape user-supplied input when generating CSV files. This allows an attacker to inject spreadsheet formulas into input fields. These formulas are executed when an administrator opens the exported CSV file using spreadsheet software like Microsoft Excel or LibreOffice Calc. CSV injection is a technique where malicious formulas are inserted into a CSV file to execute commands or steal data when opened in a spreadsheet application.
Recommendations
Update to version 3.17.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typebot