SSRF Vulnerability in Typebot Chatbot Builder Prior to Version 3.17.2
CVE-2026-49213
8.1HIGH
What is CVE-2026-49213?
Typebot, a popular chatbot builder tool, contains a vulnerability allowing for Server-Side Request Forgery (SSRF) attacks due to its flawed IP address validation mechanism. The shared SSRF validator, located in packages/lib/src/ssrf/validateHttpReqUrl.ts, can be bypassed by using the IPv6 unspecified address (::), which isn't adequately blocked. This security flaw enables a workspace editor or creator to configure HTTP request blocks or guarded scripts that can connect to local HTTP services, potentially exposing sensitive data or functionality. This vulnerability has been addressed and patched in version 3.17.2.
Affected Version(s)
typebot.io < 3.17.2
