SSRF Vulnerability in Typebot Chatbot Builder Prior to Version 3.17.2
CVE-2026-49213

8.1HIGH

Key Information:

Vendor
CVE Published:
10 July 2026

What is CVE-2026-49213?

Typebot, a popular chatbot builder tool, contains a vulnerability allowing for Server-Side Request Forgery (SSRF) attacks due to its flawed IP address validation mechanism. The shared SSRF validator, located in packages/lib/src/ssrf/validateHttpReqUrl.ts, can be bypassed by using the IPv6 unspecified address (::), which isn't adequately blocked. This security flaw enables a workspace editor or creator to configure HTTP request blocks or guarded scripts that can connect to local HTTP services, potentially exposing sensitive data or functionality. This vulnerability has been addressed and patched in version 3.17.2.

Affected Version(s)

typebot.io < 3.17.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.