Insecure Direct Object Reference Vulnerability in Typebot Open-Source Chatbot Builder
CVE-2025-64706
5MEDIUM
What is CVE-2025-64706?
Typebot, an open-source chatbot builder, is affected by an Insecure Direct Object Reference (IDOR) vulnerability in the API token management endpoint. This flaw, present in versions 3.9.0 up to but excluding 3.13.0, allows authenticated attackers to delete any user's API token and obtain its value by simply knowing the target user's ID and token ID, bypassing necessary authorization checks. The issue has been rectified in version 3.13.0.
Affected Version(s)
typebot.io >= 3.9.0, < 3.13.0
