Typebot 是一款开源的聊天机器人构建工具。在自托管版本中,从早期版本至 3.17.1(含),其默认的无密码电子邮件魔法链接认证机制存在漏洞,攻击者可通过暴力破解登录代码,从而导致账户被接管。 该漏洞的具体成因如下:电子邮件提供商覆盖了 NextAuth 默认的密码学安全令牌,改用由 生成的 6 位数字代码。这种设计将密钥空间缩小至 90 万个,且代码有效期仅为 10 分钟。此外,该代码本身直接作为原始值嵌入在魔法链接中。 验证回调函数未实施任何尝试次数限制、账户锁定机制或跨站请求伪造(CSRF)防护。更严重的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baptisteArno | typebot.io | < 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62865 | 8.7 HIGH | TypeBot: Arbitrary server file read via Send Email block attachment path |
| CVE-2026-62861 | 6.4 MEDIUM | TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomain |
No comments yet