CSV Injection Vulnerability in TypeBot Chatbot Builder Tool Version 3.16.1
CVE-2026-47705

9.6CRITICAL

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-47705?

TypeBot, a popular chatbot builder tool, is impacted by a CSV injection vulnerability in version 3.16.1. This flaw arises from the application's failure to properly sanitize or escape user inputs during the generation of CSV files. As a result, malicious users can inject harmful spreadsheet formulas into input fields. When administrators open the exported CSV files in applications like Microsoft Excel or LibreOffice Calc, these injected formulas can execute, potentially leading to unauthorized actions within the application's environment. The vulnerability is addressed in version 3.17.0, which includes necessary patches to enhance input handling and security.

Affected Version(s)

typebot.io = 3.16.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.