PT-2026-70794 · Typebot · Typebot

CVE-2026-48494

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.17.0
Description An authenticated user with read access to any typebot can resume a WhatsApp preview webhook session belonging to a different typebot. This occurs because the WhatsApp test-webhook handler authorizes the parent typebot but resolves the preview chat session using only the wa-preview-{phone} identifier. By combining an authorized typebotId and blockId with a foreign preview phone number, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft or unpublished flow without having access to the victim typebot.
Recommendations Update to version 3.17.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48494
GHSA-FQF7-MMP5-J3JQ

Affected Products

Typebot