PT-2026-81874 · Typebot · Typebot

·

CVE-2026-62861

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions TypeBot versions prior to 3.18.0
Description An issue exists where an authenticated non-guest workspace member can remove a public custom domain belonging to another workspace, rendering the chatbots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.ts authorizes the caller based on a client-supplied workspaceId but transmits the client-supplied domain name to the shared Vercel project before verifying if the domain actually belongs to the specified workspace.
Recommendations Update to version 3.18.0.

Exploit

Fix

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62861
GHSA-7H82-P425-WPMG

Affected Products

Typebot