Executive brief
Typebot is an open-source chatbot builder. A security vulnerability in the chatbot editor allows a malicious user or collaborator to create a chatbot that executes unauthorized code when viewed by an administrator or editor. This could lead to an attacker stealing login sessions, accessing sensitive workspace data, or escalating their privileges within the platform. The issue specifically affects the 'Rating' button component when a custom icon is used.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Typebot's RatingButton component due to the unsanitized use of Solid's innerHTML directive on the 'customIcon.svg' field. While Typebot employs a Web Worker sandbox to isolate untrusted scripts during bot previews, the Rating block was not included in the 'isUnsafe' sanitization list. Consequently, a malicious SVG payload (e.g., using 'onerror' handlers) executes directly in the builder's DOM context on the 'builder.typebot.io' origin. Because the builder's Content Security Policy (CSP) permits 'unsafe-inline', an attacker can bypass the sandbox to hijack session cookies or perform actions on behalf of an authenticated user. This is fixed in version 3.16.0 by implementing proper SVG sanitization.
Affected products
- baptisteArno typebot.io <= 3.15.2
Timeline
- 2026-04-08: patched: Version 3.16.0 released
- 2026-05-22: disclosed: Security advisory published