PT-2026-70916 · Typebot · Typebot

CVE-2026-48765

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.17.0
Description Low-privilege read collaborators can extract a workspace OAuth credentialsId from a readable bot configuration. By supplying an attacker-controlled writable workspaceId to the handleUpdateOAuthCredentials() function, an attacker can overwrite that credential. The update process validates only the provided workspace and updates the credential record using the global id, which also rewrites the credential's workspaceId. This flaw enables the takeover and reassignment of OAuth credentials across different workspaces.
Recommendations Update to version 3.17.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48765
GHSA-3788-7276-X4J4

Affected Products

Typebot