High severityNVD Advisory· Published Aug 11, 2026· Updated Sep 9, 2026
CVE-2026-47704
CVE-2026-47704
Description
TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing an authorized typebotId and blockId and a foreign live resultId. The webhook resume handler authorizes the parent typebot first, but then resolves the descendant result only by resultId. As a result, an attacker can inject arbitrary webhook JSON into another typebot's suspended session and advance its execution without any access to the victim typebot. Version 3.17.0 patches the issue.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.