Executive brief
TypeBot, a chatbot building platform, contains a security flaw that allows users to modify or delete chatbot theme templates belonging to other organizations or workspaces. By exploiting this issue, an authorized user on the platform could intentionally corrupt or remove the visual branding and design templates of other customers. This could lead to unauthorized design changes or service disruptions for affected chatbot users.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the handleSaveThemeTemplate and handleDeleteThemeTemplate handlers of TypeBot. While the application validates that the requesting user is a member of the workspace ID provided in the request, the subsequent Prisma database queries for updating or deleting templates use only the themeTemplateId in the WHERE clause. Because the workspaceId is not included in the database filter, an attacker can provide their own valid workspace ID to pass the initial authorization check while targeting a template ID belonging to a different workspace. This allows for cross-workspace modification and deletion of templates. The vulnerability is fixed in version 3.16.0 by ensuring database operations are scoped to both the template ID and the verified workspace ID.
Affected products
- baptisteArno typebot.io <= 3.15.2
Timeline
- 2026-04-08: patched: Version 3.16.0 released
- 2026-05-24: advisory: GitHub Security Advisory published
- 2026-06-17: disclosed: CVE published to NVD