Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-62861— TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomain

Quick assessment

Affected
baptisteArno typebot.io
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TypeBot 是一款聊天机器人构建工具。在 3.18.0 版本之前,任何经过身份验证的非访客工作区成员可以移除另一个工作区的公共自定义域名,导致该域名上的 TypeBot 不可用。handleDeleteCustomDomain.ts 中的自定义域名删除处理程序会根据客户端提供的工作区 ID 对调用者进行授权,但在验证该域名是否属于该工作区之前,会将客户端提供的域名名称发送给共享的 Vercel 项目。此问题已在 3.18.0 版本中得到修复。

CVSS 6.4 · Medium EPSS 0.40% · P33

Affected Version Matrix 1

VendorProduct Version RangeStatus
baptisteArno typebot.io < 3.18.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-62861

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomain
Source: CVE Program / CVE List V5
Vulnerability Description
TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.ts authorizes a caller against a client-supplied workspaceId but sends the client-supplied domain name to the shared Vercel project before verifying that the domain belongs to that workspace. This issue is fixed in version 3.18.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
baptisteArno typebot.io < 3.18.0 -

II. Public POCs for CVE-2026-62861

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62861

登录查看更多情报信息。

Patches & Fixes for CVE-2026-62861 (1)

Vendor Advisories for CVE-2026-62861 (1)

Vendor Pages for CVE-2026-62861 (1)

Same Patch Batch · baptisteArno · 2026-08-25 · 3 CVEs total

CVE-2026-62862 9.1 CRITICAL TypeBot: Account takeover via brute-forceable 6-digit magic-link code
CVE-2026-62865 8.7 HIGH TypeBot: Arbitrary server file read via Send Email block attachment path

IV. Related Vulnerabilities

V. Comments for CVE-2026-62861

No comments yet


Leave a comment