Unauthenticated Workspace Domain Management Issue in TypeBot by Baptiste Arno
CVE-2026-62861

6.4MEDIUM

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-62861?

TypeBot, a chatbot builder tool, has a vulnerability that permits authenticated non-guest workspace members to remove another workspace's public custom domain. This flaw arises from the custom-domain deletion process, where it improperly authorizes actions using a client-supplied workspace ID but fails to verify the domain ownership against the workspace. Consequently, this could lead to unauthorized users making Typebots on that domain unavailable. The issue has been addressed in version 3.18.0.

Affected Version(s)

typebot.io < 3.18.0

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.