PT-2026-70793 · Typebot · Typebot

CVE-2026-47705

·

Published

2026-08-11

·

Updated

2026-08-13

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.17.0
Description The result export functionality fails to sanitize or escape user-supplied input when generating CSV files. This allows an attacker to inject spreadsheet formulas into input fields. These formulas are executed when an administrator opens the exported CSV file using spreadsheet software like Microsoft Excel or LibreOffice Calc. CSV injection is a technique where malicious formulas are inserted into a CSV file to execute commands or steal data when opened in a spreadsheet application.
Recommendations Update to version 3.17.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47705
GHSA-P52M-H5QG-8P8W

Affected Products

Typebot