Baptiste Arnaud Typebot是Baptiste Arnaud个人开发者的一个可视化聊天机器人构建平台。 Baptiste Arnaud Typebot 3.17.0之前版本存在信息泄露漏洞,该漏洞源于权限检查不当,允许低权限访客成员通过攻击者控制的baseUrl调用OpenAI模型列表助手,导致存储的OpenAI兼容API密钥被泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| baptisteArno | typebot.io | < 3.17.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baptisteArno | typebot.io | < 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48765 | 9.9 CRITICAL | TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials |
| CVE-2026-47705 | 9.6 CRITICAL | TypeBot vulnerable to CSV injection in result export |
| CVE-2026-47702 | 9.1 CRITICAL | TypeBot API tokens stored in plaintext |
| CVE-2026-48763 | 8.2 HIGH | TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-co |
| CVE-2026-48767 | 7.6 HIGH | Google Sheets OAuth access token disclosure to guest members via getAccessToken |
| CVE-2026-42142 | 7.1 HIGH | TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-W |
| CVE-2026-48495 | 7.1 HIGH | TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and |
| CVE-2026-47704 | 7.1 HIGH | TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows |
| CVE-2026-48494 | 7.1 HIGH | TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview |
| CVE-2026-48483 | 5.4 MEDIUM | TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF |
| CVE-2026-48762 | 5.4 MEDIUM | TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler |
No comments yet