Junglewise Threat Intelligence

CVE-2026-39965: baptisteArno TypeBot SSRF via redirect bypass in HTTP and Code blocks

CVE-2026-39965 · Severity: high · CVSS 7.7 · Published 2026-05-22

Technologies: Typebot. Vendors: Typebot.

Executive brief

TypeBot is an open-source chatbot builder that allows users to create conversational interfaces. A security flaw in how the system handles web requests allows authenticated users to trick the TypeBot server into connecting to internal company systems or cloud infrastructure services that are not supposed to be accessible from the internet. This could lead to the theft of sensitive cloud credentials (such as AWS IAM roles) or the exposure of private internal data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in TypeBot's HTTP Request and Code blocks. While the application uses a validation function (validateHttpReqUrl) to block requests to private IPs and cloud metadata endpoints, the underlying HTTP clients (ky and fetch) are configured to follow 302 redirects automatically. An attacker can provide a URL to a malicious server that passes initial validation but then issues a redirect to a restricted internal IP (e.g., 169.254.169.254 or 172.x.x.x). Because the redirect destination is not re-validated, the server fetches the internal resource and returns the content to the attacker. This can be used to extract cloud credentials or map internal infrastructure. The issue is fixed in version 3.16.0 by ensuring redirects are handled manually or re-validated.

Affected products

  • baptisteArno typebot.io <= 3.15.2

Timeline

  • 2026-04-08: patched: Version 3.16.0 released with fix.
  • 2026-05-22: disclosed: Security advisory published.

References

Related threats