Insecure Direct Object Reference in TypeBot Chatbot Builder Tool by Baptiste Arno
CVE-2026-48759
7.1HIGH
What is CVE-2026-48759?
TypeBot, a chatbot builder by Baptiste Arno, is susceptible to an Insecure Direct Object Reference that affects versions 3.15.2 and earlier. This vulnerability arises from improper validation in the handling of theme templates, enabling authenticated users to alter or delete theme templates across different workspaces. The handleSaveThemeTemplate and handleDeleteThemeTemplate functionalities fail to properly restrict access by not including the workspace identifier in their queries, potentially exposing sensitive Template IDs through shared typebots or network transmissions. The issue has been remedied in version 3.16.0.
Affected Version(s)
typebot.io < 3.16.0
