Token Exposure Vulnerability in TypeBot by Baptiste Arno
CVE-2026-48767
7.6HIGH
What is CVE-2026-48767?
TypeBot, a chatbot builder tool, has a vulnerability in versions prior to 3.17.0 that exposes Google Sheets OAuth access tokens to low-privilege guest members. This issue arises because the access control checks only validate read access, allowing guest members to decrypt stored Google OAuth credentials and retrieve raw bearer tokens directly. As guests can enumerate credential identifiers, they can abuse this flaw to mint and reuse the workspace's Google access token beyond TypeBot, posing serious security risks. The vulnerability has been patched in version 3.17.0.
Affected Version(s)
typebot.io < 3.17.0
