Improper Access Control in TypeBot Chatbot Builder Tool May Lead to Data Exposure
CVE-2026-42142
7.1HIGH
What is CVE-2026-42142?
TypeBot, a popular chatbot builder, has a vulnerability in the handleGetSheets API handler (POST /api/sheets/getSheets). This flaw, present in versions prior to 3.17.0, allows any authenticated user to bypass workspace membership validation, resulting in unauthorized access to another workspace's Google Sheets OAuth credentials. This could enable malicious users to decrypt sensitive information, including spreadsheet data such as sheet names and IDs. The issue has been addressed in version 3.17.0, which includes robust validation mechanisms to prevent such unauthorized access.
Affected Version(s)
typebot.io < 3.17.0
