Improper Access Control in TypeBot Chatbot Builder Tool May Lead to Data Exposure
CVE-2026-42142

7.1HIGH

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-42142?

TypeBot, a popular chatbot builder, has a vulnerability in the handleGetSheets API handler (POST /api/sheets/getSheets). This flaw, present in versions prior to 3.17.0, allows any authenticated user to bypass workspace membership validation, resulting in unauthorized access to another workspace's Google Sheets OAuth credentials. This could enable malicious users to decrypt sensitive information, including spreadsheet data such as sheet names and IDs. The issue has been addressed in version 3.17.0, which includes robust validation mechanisms to prevent such unauthorized access.

Affected Version(s)

typebot.io < 3.17.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.