Executive brief
TypeBot is a chatbot builder tool that allows administrators to export conversation results to CSV files. Version 3.16.1 fails to sanitize user input in exported data, allowing attackers to inject spreadsheet formulas that execute when administrators open the CSV file in Microsoft Excel or LibreOffice Calc. This could lead to data theft, malware installation, or account compromise.
Technical details
The vulnerability is a CSV formula injection (CWE-1236) in the result export functionality. The application does not escape or sanitize user-supplied input when generating CSV files, allowing attackers to inject formulas by including values starting with =, +, -, @, tab, or carriage return characters in chatbot input fields. When an administrator exports results to CSV and opens the file in spreadsheet software, these formulas are automatically executed. The attack requires that an administrator export the results and open the file, but no authentication is needed to submit malicious input to the chatbot. Version 3.17.0 patches the issue by implementing a sanitizeCsvCell helper function that prepends an apostrophe to values starting with formula-triggering characters.
Affected products
- TypeBot TypeBot 3.16.1
Timeline
- 2026-08-11: disclosed
- 2026-05-19: patched: Fix merged in version 3.17.0