OAuth Credential Vulnerability in TypeBot by Baptiste Arno
CVE-2026-48765

9.9CRITICAL

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48765?

TypeBot, a popular chatbot builder tool, is susceptible to an OAuth credential vulnerability where low-privilege users can exploit a bot configuration to hijack workspace OAuth credentials. In versions before 3.17.0, attackers can leverage the handleUpdateOAuthCredentials() function by supplying a writable workspaceId, which allows them to overwrite existing credentials due to inadequate validation processes. This flaw poses a significant risk of unauthorized access to bot configurations and sensitive user data across different workspaces.

Affected Version(s)

typebot.io < 3.17.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.