← Späť na vyhľadávanie CVE

CVE-2026-39964

Typebot

Popis

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme. A bot author can set a link URL to javascript:PAYLOAD, which executes in the visitor-s browser context when clicked. Since the viewer is typically embedded in a third-party site, the attacker-s JavaScript runs in the host page-s origin and can exfiltrate cookies and session tokens. This can result in any authenticated Typebot user (including those on the free tier) being able to create a bot with this payload. Shared bots are publicly accessible — no victim authentication is required. This issue has been resolved in version 3.16.0.

CVSS 5.4EPSS 0.241%Riziko 0.55
Zobraziť zdroj
Zverejnené
2026-05-22 18:16:21
Dotknuté verzie
< 3.16.0
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N