CVE-2026-47702

Source
https://cve.org/CVERecord?id=CVE-2026-47702
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47702.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47702
Aliases
  • GHSA-9c96-gcg3-2662
Published
2026-08-11T14:03:22Z
Modified
2026-08-13T04:02:29Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
TypeBot API tokens stored in plaintext
Details

TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication. Version 3.17.0 fixes the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-312"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47702.json"
}
References

Affected packages

Git / github.com/baptistearno/typebot.io

Affected ranges

Type
GIT
Repo
https://github.com/baptistearno/typebot.io
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "= 3.16.1"
        },
        {
            "last_affected": "= 3.16.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

= 3.*
= 3.16.1
js-v0.*
js-v0.10.2
react-v0.*
react-v0.10.2
v3.*
v3.16.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47702.json"