Junglewise Threat Intelligence

CVE-2026-34207: baptisteArno TypeBot SSRF in Webhook and HTTP Request blocks

CVE-2026-34207 · Severity: high · CVSS 7.6 · Published 2026-05-22

Executive brief

TypeBot, a tool used to build and host interactive chatbots, contains a security flaw in how it handles external web requests. An attacker with basic user permissions could bypass security filters to force the server to connect to internal systems, such as private databases or cloud management services. This could lead to the exposure of sensitive internal data or unauthorized access to the organization's private cloud infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in TypeBot's Webhook and HTTP Request blocks due to insufficient validation in the `validateHttpReqUrl` component. The application validates URL strings against a blacklist of literal hostnames and IP formats but does not resolve DNS before the request is executed. An attacker can provide a custom hostname that resolves to a restricted IP address (such as 127.0.0.1, 169.254.169.254, or RFC1918 private ranges), bypassing the filter. This allows the attacker to reach loopback services, cloud metadata endpoints, and internal network targets. The issue is fixed in version 3.16.0 by implementing DNS resolution during validation and using a hardened HTTP client (`safeKy`).

Affected products

  • baptisteArno typebot.io < 3.16.0

Timeline

  • 2026-04-07: patched: Fix committed to repository
  • 2026-04-08: other: Version 3.16.0 released
  • 2026-05-22: disclosed: Security advisory published

References