Insecure Direct Object Reference Vulnerability in Typebot Open-Source Chatbot Builder
CVE-2025-64706

5MEDIUM

Key Information:

Vendor
CVE Published:
13 November 2025

What is CVE-2025-64706?

Typebot, an open-source chatbot builder, is affected by an Insecure Direct Object Reference (IDOR) vulnerability in the API token management endpoint. This flaw, present in versions 3.9.0 up to but excluding 3.13.0, allows authenticated attackers to delete any user's API token and obtain its value by simply knowing the target user's ID and token ID, bypassing necessary authorization checks. The issue has been rectified in version 3.13.0.

Affected Version(s)

typebot.io >= 3.9.0, < 3.13.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64706 : Insecure Direct Object Reference Vulnerability in Typebot Open-Source Chatbot Builder