Webhook Vulnerability in TypeBot for WhatsApp Cloud API
CVE-2026-39969

6.5MEDIUM

Key Information:

Vendor
CVE Published:
22 May 2026

What is CVE-2026-39969?

TypeBot, a chatbot builder tool, has a webhook security issue affecting versions up to 3.16.0. The WhatsApp Cloud API webhook endpoint fails to verify the HMAC signature included in each delivery by Meta. This flaw allows unauthenticated attackers to send fraudulent webhook messages, triggering bot flows, consuming API resources, and executing actions as if they were the workspace owner. The vulnerability exposes sensitive identifiers, such as workspaceId and credentialsId, which are logged in server access logs and can be viewed in Meta's webhook configuration dashboard. A fix has been implemented in version 3.17.0.

Affected Version(s)

typebot.io < 3.17.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.