OAuth Credential Vulnerability in TypeBot by Baptiste Arno
CVE-2026-48765
9.9CRITICAL
What is CVE-2026-48765?
TypeBot, a popular chatbot builder tool, is susceptible to an OAuth credential vulnerability where low-privilege users can exploit a bot configuration to hijack workspace OAuth credentials. In versions before 3.17.0, attackers can leverage the handleUpdateOAuthCredentials() function by supplying a writable workspaceId, which allows them to overwrite existing credentials due to inadequate validation processes. This flaw poses a significant risk of unauthorized access to bot configurations and sensitive user data across different workspaces.
Affected Version(s)
typebot.io < 3.17.0
