漏洞描述: Typebot 是一款开源的聊天机器人构建工具。在 3.18.0 版本之前的自托管(self-hosted)版本中,其服务器端的“发送电子邮件”(Send Email)集成模块存在任意本地文件读取漏洞。 该模块通过 Typebot 变量来构建 Nodemailer 邮件附件。其内部的 辅助函数在处理附件路径时存在缺陷:当输入值不以应用程序自身的基础 URL 开头时,它会将该值直接视为文件系统路径返回,而不是要求必须提供以 或 开头的有效网络 URL。 同时,创建的 Nodemailer 传输对象未启用
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| baptisteArno | typebot.io | < 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62862 | 9.1 CRITICAL | TypeBot: Account takeover via brute-forceable 6-digit magic-link code |
| CVE-2026-62861 | 6.4 MEDIUM | TypeBot: Cross-tenant custom-domain removal via unbound `name` in handleDeleteCustomDomain |
No comments yet