{"schema_version":1,"title":"Typebot vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in Typebot: 0 in the last 7 days and 9 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-62865, was published on 25 August 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/typebot","json_url":"https://junglewise.ai/threats/vendors/typebot.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/typebot","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":8,"all_time":19,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":19},"latest":[{"cve":"CVE-2026-62865","cvss":7.5,"epss":0.0032,"slug":"cve-2026-62865-typebot-arbitrary-local-file-read-via-send-email-attachment","title":"Typebot arbitrary local file read via Send Email attachment","severity":"info","exploited":false,"published_at":"2026-08-25T22:17:04.473+00:00","url":"https://junglewise.ai/threats/cve-2026-62865-typebot-arbitrary-local-file-read-via-send-email-attachment"},{"cve":"CVE-2026-62861","cvss":0,"epss":0.0041,"slug":"cve-2026-62861-typebot-custom-domain-deletion-authorization-bypass","title":"TypeBot custom domain deletion authorization bypass","severity":"info","exploited":false,"published_at":"2026-08-25T22:17:04.177+00:00","url":"https://junglewise.ai/threats/cve-2026-62861-typebot-custom-domain-deletion-authorization-bypass"},{"cve":"CVE-2026-48767","cvss":7.6,"epss":0.0043,"slug":"cve-2026-48767-typebot-privilege-escalation-in-google-sheets-integration","title":"TypeBot privilege escalation in Google Sheets integration","severity":"high","exploited":false,"published_at":"2026-08-11T18:17:33.47+00:00","url":"https://junglewise.ai/threats/cve-2026-48767-typebot-privilege-escalation-in-google-sheets-integration"},{"cve":"CVE-2026-48494","epss":0.0047,"slug":"cve-2026-48494-typebot-whatsapp-preview-webhook-authorization-bypass","title":"TypeBot WhatsApp preview webhook authorization bypass","severity":"info","exploited":false,"published_at":"2026-08-11T18:17:33.31+00:00","url":"https://junglewise.ai/threats/cve-2026-48494-typebot-whatsapp-preview-webhook-authorization-bypass"},{"cve":"CVE-2026-47705","cvss":9.6,"epss":0.0056,"slug":"cve-2026-47705-typebot-csv-injection-in-result-export","title":"TypeBot CSV injection in result export","severity":"critical","exploited":false,"published_at":"2026-08-11T18:17:27.123+00:00","url":"https://junglewise.ai/threats/cve-2026-47705-typebot-csv-injection-in-result-export"},{"cve":"CVE-2026-48766","cvss":7.6,"epss":0.0043,"slug":"cve-2026-48766-typebot-chatbot-builder-api-key-exfiltration-via-guest-access","title":"TypeBot chatbot builder API key exfiltration via guest access","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:32.32+00:00","url":"https://junglewise.ai/threats/cve-2026-48766-typebot-chatbot-builder-api-key-exfiltration-via-guest-access"},{"cve":"CVE-2026-48495","cvss":7.1,"epss":0.0035,"slug":"cve-2026-48495-typebot-google-sheets-oauth-callback-privilege-escalation","title":"TypeBot Google Sheets OAuth callback privilege escalation","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:32.17+00:00","url":"https://junglewise.ai/threats/cve-2026-48495-typebot-google-sheets-oauth-callback-privilege-escalation"},{"cve":"CVE-2026-42142","cvss":7.1,"epss":0.0037,"slug":"cve-2026-42142-typebot-authorization-bypass-in-getsheets-endpoint","title":"TypeBot authorization bypass in getSheets endpoint","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:31.9+00:00","url":"https://junglewise.ai/threats/cve-2026-42142-typebot-authorization-bypass-in-getsheets-endpoint"},{"cve":"CVE-2026-49213","cvss":8.1,"slug":"cve-2026-49213-baptistearno-typebot-ssrf-bypass-via-ipv6-unspecified-address","title":"baptisteArno TypeBot SSRF bypass via IPv6 unspecified address","severity":"high","exploited":false,"published_at":"2026-07-10T22:16:42.27+00:00","url":"https://junglewise.ai/threats/cve-2026-49213-baptistearno-typebot-ssrf-bypass-via-ipv6-unspecified-address"},{"cve":"CVE-2026-48768","cvss":9.3,"epss":0.0027,"slug":"cve-2026-48768-baptistearno-typebot-unauthenticated-s3-object-write-in-generate","title":"baptisteArno TypeBot unauthenticated S3 object write in generate-upload-url","severity":"critical","exploited":false,"published_at":"2026-06-18T00:16:23.887+00:00","url":"https://junglewise.ai/threats/cve-2026-48768-baptistearno-typebot-unauthenticated-s3-object-write-in-generate"},{"cve":"CVE-2026-48759","cvss":7.1,"epss":0.002,"slug":"cve-2026-48759-baptistearno-typebot-idor-in-theme-template-handlers","title":"baptisteArno TypeBot IDOR in theme template handlers","severity":"high","exploited":false,"published_at":"2026-06-17T23:17:04.173+00:00","url":"https://junglewise.ai/threats/cve-2026-48759-baptistearno-typebot-idor-in-theme-template-handlers"},{"cve":"CVE-2026-39970","cvss":8.5,"epss":0.0028,"slug":"cve-2026-39970-baptistearno-typebot-stored-xss-in-profile-picture-upload","title":"baptisteArno TypeBot stored XSS in profile picture upload","severity":"info","exploited":false,"published_at":"2026-05-22T19:17:03.633+00:00","url":"https://junglewise.ai/threats/cve-2026-39970-baptistearno-typebot-stored-xss-in-profile-picture-upload"},{"cve":"CVE-2026-39969","cvss":6.5,"epss":0.0014,"slug":"cve-2026-39969-baptistearno-typebot-insufficient-signature-verification-in","title":"baptisteArno TypeBot insufficient signature verification in WhatsApp webhook","severity":"medium","exploited":false,"published_at":"2026-05-22T19:17:03.5+00:00","url":"https://junglewise.ai/threats/cve-2026-39969-baptistearno-typebot-insufficient-signature-verification-in"},{"cve":"CVE-2026-39968","cvss":7.1,"epss":0.0004,"slug":"cve-2026-39968-typebot-cross-workspace-credential-theft-in-bot-engine-preview","title":"TypeBot cross-workspace credential theft in bot-engine preview endpoint","severity":"high","exploited":false,"published_at":"2026-05-22T19:17:03.373+00:00","url":"https://junglewise.ai/threats/cve-2026-39968-typebot-cross-workspace-credential-theft-in-bot-engine-preview"},{"cve":"CVE-2026-39967","cvss":3.1,"epss":0.0003,"slug":"cve-2026-39967-baptistearno-typebot-authorization-bypass-in-bot-engine","title":"baptisteArno TypeBot authorization bypass in bot engine","severity":"low","exploited":false,"published_at":"2026-05-22T19:17:03.243+00:00","url":"https://junglewise.ai/threats/cve-2026-39967-baptistearno-typebot-authorization-bypass-in-bot-engine"},{"cve":"CVE-2026-39965","cvss":7.7,"epss":0.0024,"slug":"cve-2026-39965-baptistearno-typebot-ssrf-via-redirect-bypass-in-http-and-code","title":"baptisteArno TypeBot SSRF via redirect bypass in HTTP and Code blocks","severity":"high","exploited":false,"published_at":"2026-05-22T18:16:21.857+00:00","url":"https://junglewise.ai/threats/cve-2026-39965-baptistearno-typebot-ssrf-via-redirect-bypass-in-http-and-code"},{"cve":"CVE-2026-39964","cvss":5.4,"epss":0.0033,"slug":"cve-2026-39964-baptistearno-typebot-stored-xss-in-text-bubble-links","title":"baptisteArno TypeBot stored XSS in text bubble links","severity":"medium","exploited":false,"published_at":"2026-05-22T18:16:21.69+00:00","url":"https://junglewise.ai/threats/cve-2026-39964-baptistearno-typebot-stored-xss-in-text-bubble-links"},{"cve":"CVE-2026-28444","cvss":6.5,"epss":0.0032,"slug":"cve-2026-28444-typebot-idor-in-getresultlogs-api-endpoint","title":"Typebot IDOR in getResultLogs API endpoint","severity":"medium","exploited":false,"published_at":"2026-05-22T17:16:45.97+00:00","url":"https://junglewise.ai/threats/cve-2026-28444-typebot-idor-in-getresultlogs-api-endpoint"},{"cve":"CVE-2025-65098","cvss":3.1,"epss":0.0035,"slug":"cve-2025-65098-typebot-credential-theft-via-client-side-script-execution","title":"Typebot credential theft via client-side script execution","severity":"low","exploited":false,"published_at":"2026-01-22T18:02:12+00:00","url":"https://junglewise.ai/threats/cve-2025-65098-typebot-credential-theft-via-client-side-script-execution"}],"vendor":{"hub":true,"name":"Typebot","slug":"typebot","homepage":"https://typebot.io/","description":"Typebot is an open-source platform for building conversational forms and chatbots.","url":"https://junglewise.ai/threats/vendors/typebot"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":6},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-47705","cvss":9.6,"epss":0.0056,"slug":"cve-2026-47705-typebot-csv-injection-in-result-export","title":"TypeBot CSV injection in result export","severity":"critical","exploited":false,"published_at":"2026-08-11T18:17:27.123+00:00","url":"https://junglewise.ai/threats/cve-2026-47705-typebot-csv-injection-in-result-export"},{"cve":"CVE-2026-48768","cvss":9.3,"epss":0.0027,"slug":"cve-2026-48768-baptistearno-typebot-unauthenticated-s3-object-write-in-generate","title":"baptisteArno TypeBot unauthenticated S3 object write in generate-upload-url","severity":"critical","exploited":false,"published_at":"2026-06-18T00:16:23.887+00:00","url":"https://junglewise.ai/threats/cve-2026-48768-baptistearno-typebot-unauthenticated-s3-object-write-in-generate"},{"cve":"CVE-2026-49213","cvss":8.1,"slug":"cve-2026-49213-baptistearno-typebot-ssrf-bypass-via-ipv6-unspecified-address","title":"baptisteArno TypeBot SSRF bypass via IPv6 unspecified address","severity":"high","exploited":false,"published_at":"2026-07-10T22:16:42.27+00:00","url":"https://junglewise.ai/threats/cve-2026-49213-baptistearno-typebot-ssrf-bypass-via-ipv6-unspecified-address"},{"cve":"CVE-2026-39965","cvss":7.7,"epss":0.0024,"slug":"cve-2026-39965-baptistearno-typebot-ssrf-via-redirect-bypass-in-http-and-code","title":"baptisteArno TypeBot SSRF via redirect bypass in HTTP and Code blocks","severity":"high","exploited":false,"published_at":"2026-05-22T18:16:21.857+00:00","url":"https://junglewise.ai/threats/cve-2026-39965-baptistearno-typebot-ssrf-via-redirect-bypass-in-http-and-code"},{"cve":"CVE-2026-48767","cvss":7.6,"epss":0.0043,"slug":"cve-2026-48767-typebot-privilege-escalation-in-google-sheets-integration","title":"TypeBot privilege escalation in Google Sheets integration","severity":"high","exploited":false,"published_at":"2026-08-11T18:17:33.47+00:00","url":"https://junglewise.ai/threats/cve-2026-48767-typebot-privilege-escalation-in-google-sheets-integration"},{"cve":"CVE-2026-48766","cvss":7.6,"epss":0.0043,"slug":"cve-2026-48766-typebot-chatbot-builder-api-key-exfiltration-via-guest-access","title":"TypeBot chatbot builder API key exfiltration via guest access","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:32.32+00:00","url":"https://junglewise.ai/threats/cve-2026-48766-typebot-chatbot-builder-api-key-exfiltration-via-guest-access"},{"cve":"CVE-2026-42142","cvss":7.1,"epss":0.0037,"slug":"cve-2026-42142-typebot-authorization-bypass-in-getsheets-endpoint","title":"TypeBot authorization bypass in getSheets endpoint","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:31.9+00:00","url":"https://junglewise.ai/threats/cve-2026-42142-typebot-authorization-bypass-in-getsheets-endpoint"},{"cve":"CVE-2026-48495","cvss":7.1,"epss":0.0035,"slug":"cve-2026-48495-typebot-google-sheets-oauth-callback-privilege-escalation","title":"TypeBot Google Sheets OAuth callback privilege escalation","severity":"high","exploited":false,"published_at":"2026-08-11T16:17:32.17+00:00","url":"https://junglewise.ai/threats/cve-2026-48495-typebot-google-sheets-oauth-callback-privilege-escalation"},{"cve":"CVE-2026-48759","cvss":7.1,"epss":0.002,"slug":"cve-2026-48759-baptistearno-typebot-idor-in-theme-template-handlers","title":"baptisteArno TypeBot IDOR in theme template handlers","severity":"high","exploited":false,"published_at":"2026-06-17T23:17:04.173+00:00","url":"https://junglewise.ai/threats/cve-2026-48759-baptistearno-typebot-idor-in-theme-template-handlers"},{"cve":"CVE-2026-39968","cvss":7.1,"epss":0.0004,"slug":"cve-2026-39968-typebot-cross-workspace-credential-theft-in-bot-engine-preview","title":"TypeBot cross-workspace credential theft in bot-engine preview endpoint","severity":"high","exploited":false,"published_at":"2026-05-22T19:17:03.373+00:00","url":"https://junglewise.ai/threats/cve-2026-39968-typebot-cross-workspace-credential-theft-in-bot-engine-preview"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Typebot","slug":"typebot","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/typebot"}]}