Webhook Execution Flaw in TypeBot Affecting Authorized Users
CVE-2026-47704

7.1HIGH

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-47704?

TypeBot, a versatile chatbot builder tool, is susceptible to a vulnerability that allows an authenticated user with read access to resume a webhook session from a different typebot. By manipulating an authorized typebotId and blockId alongside a foreign resultId, an attacker can inject arbitrary JSON into another typebot's suspended session, thereby advancing its execution without direct access to the targeted typebot. This security issue, addressed in version 3.17.0, underlines the importance of rigorous authorization checks.

Affected Version(s)

typebot.io < 3.17.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.