Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-48765: TypeBot versions prior to 3.17.0: OAuth credential takeover risk

CVE-2026-48765 · published 23 days ago
Summary

Versions of TypeBot before 3.17.0 are vulnerable to an attacker taking control of a workspace's OAuth credentials. This could happen if an attacker has limited access to a workspace and can view its settings. To fix this issue, update TypeBot to version 3.17.0 or later.

Original advisory text
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite...
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable `workspaceId`. The update path validates only the attacker-supplied workspace and then updates the credential record by global `id` alone, while also rewriting the credential's `workspaceId`. This allows cross-workspace OAuth credential takeover and reassignment. Version 3.17.0 patches the issue.
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published11 Aug 2026
Updated29 Aug 2026
First seen11 Aug 2026
Sources
Monitor software like this
Free during beta