PT-2026-70794 · Typebot · Typebot
CVE-2026-48494
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TypeBot versions prior to 3.17.0
Description
An authenticated user with read access to any typebot can resume a WhatsApp preview webhook session belonging to a different typebot. This occurs because the WhatsApp test-webhook handler authorizes the parent typebot but resolves the preview chat session using only the
wa-preview-{phone} identifier. By combining an authorized typebotId and blockId with a foreign preview phone number, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft or unpublished flow without having access to the victim typebot.Recommendations
Update to version 3.17.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Typebot