Webhook Vulnerability in TypeBot for WhatsApp Cloud API
CVE-2026-39969
6.5MEDIUM
What is CVE-2026-39969?
TypeBot, a chatbot builder tool, has a webhook security issue affecting versions up to 3.16.0. The WhatsApp Cloud API webhook endpoint fails to verify the HMAC signature included in each delivery by Meta. This flaw allows unauthenticated attackers to send fraudulent webhook messages, triggering bot flows, consuming API resources, and executing actions as if they were the workspace owner. The vulnerability exposes sensitive identifiers, such as workspaceId and credentialsId, which are logged in server access logs and can be viewed in Meta's webhook configuration dashboard. A fix has been implemented in version 3.17.0.
Affected Version(s)
typebot.io < 3.17.0
