Unauthenticated Workspace Domain Management Issue in TypeBot by Baptiste Arno
CVE-2026-62861
6.4MEDIUM
What is CVE-2026-62861?
TypeBot, a chatbot builder tool, has a vulnerability that permits authenticated non-guest workspace members to remove another workspace's public custom domain. This flaw arises from the custom-domain deletion process, where it improperly authorizes actions using a client-supplied workspace ID but fails to verify the domain ownership against the workspace. Consequently, this could lead to unauthorized users making Typebots on that domain unavailable. The issue has been addressed in version 3.18.0.
Affected Version(s)
typebot.io < 3.18.0
