VYPR
High severity8.1NVD Advisory· Published Apr 4, 2024· Updated Jun 17, 2026

CVE-2024-30264

CVE-2024-30264

Description

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the redirectPath parameter from the URL. If a user clicks on a link where the redirectPath parameter has a javascript scheme, the attacker that crafted the link may be able to execute arbitrary JavaScript with the privileges of the user. Version 2.24.0 contains a patch for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Typebot/Typebot2 versions
    cpe:2.3:a:typebot:typebot:*:*:*:*:*:-:*:*+ 1 more
    • cpe:2.3:a:typebot:typebot:*:*:*:*:*:-:*:*range: <2.24.0
    • (no CPE)range: <2.24.0
  • Baptistearno/Typebot.iollm-fuzzy2 versions
    <2.24.0+ 1 more
    • (no CPE)range: <2.24.0
    • (no CPE)range: < 2.24.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.