Baptiste Arnaud Typebot是Baptiste Arnaud个人开发者的一个可视化聊天机器人构建平台。 Baptiste Arnaud Typebot 3.17.0之前版本存在服务端请求伪造漏洞,该漏洞源于WhatsApp状态转发功能存储的webhook转发URL仅通过通用URL验证,但转发代码使用了原始ky实例而非SSRF保护的safeKy客户端,可能导致攻击者利用服务器向内部服务、私有网络主机、localhost或元数据端点发起HTTP请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| baptisteArno | typebot.io | < 3.17.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baptisteArno | typebot.io | < 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48765 | 9.9 CRITICAL | TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials |
| CVE-2026-47705 | 9.6 CRITICAL | TypeBot vulnerable to CSV injection in result export |
| CVE-2026-47702 | 9.1 CRITICAL | TypeBot API tokens stored in plaintext |
| CVE-2026-48763 | 8.2 HIGH | TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-co |
| CVE-2026-48766 | 7.6 HIGH | TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled ba |
| CVE-2026-48767 | 7.6 HIGH | Google Sheets OAuth access token disclosure to guest members via getAccessToken |
| CVE-2026-42142 | 7.1 HIGH | TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-W |
| CVE-2026-48495 | 7.1 HIGH | TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and |
| CVE-2026-47704 | 7.1 HIGH | TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows |
| CVE-2026-48494 | 7.1 HIGH | TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview |
| CVE-2026-48762 | 5.4 MEDIUM | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler |
No comments yet