Authentication Bypass in TypeBot Chatbot Builder
CVE-2026-48766
7.6HIGH
What is CVE-2026-48766?
TypeBot, a popular chatbot builder tool, has a vulnerability that permits low-privilege guest members to extract stored OpenAI-compatible API keys. This security flaw arises from the ability of a guest to invoke the OpenAI model-listing helper using a user-controlled base URL, which allows them to access sensitive workspace credentials. The flaw is due to inadequate permission checks that inadvertently expose critical identifiers to unauthorized users. As a result, an attacker can orchestrate a request that leads to the exposure of sensitive API keys. The issue has been resolved in version 3.17.0, which addresses the underlying concerns and ensures the security of user data.
Affected Version(s)
typebot.io < 3.17.0
