Authentication Bypass in TypeBot Chatbot Builder
CVE-2026-48766

7.6HIGH

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48766?

TypeBot, a popular chatbot builder tool, has a vulnerability that permits low-privilege guest members to extract stored OpenAI-compatible API keys. This security flaw arises from the ability of a guest to invoke the OpenAI model-listing helper using a user-controlled base URL, which allows them to access sensitive workspace credentials. The flaw is due to inadequate permission checks that inadvertently expose critical identifiers to unauthorized users. As a result, an attacker can orchestrate a request that leads to the exposure of sensitive API keys. The issue has been resolved in version 3.17.0, which addresses the underlying concerns and ensures the security of user data.

Affected Version(s)

typebot.io < 3.17.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.