CVE-2026-47705

Source
https://cve.org/CVERecord?id=CVE-2026-47705
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47705.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47705
Aliases
  • GHSA-p52m-h5qg-8p8w
Published
2026-08-11T17:16:12.310Z
Modified
2026-08-15T11:31:14.164786592Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
TypeBot vulnerable to CSV injection in result export
Details

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue.

Database specific
{
    "cwe_ids": [
        "CWE-1236"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47705.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/baptistearno/typebot.io

Affected ranges

Type
GIT
Repo
https://github.com/baptistearno/typebot.io
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "= 3.16.1"
        },
        {
            "last_affected": "= 3.16.1"
        }
    ]
}

Affected versions

= 3.*
= 3.16.1
js-v0.*
js-v0.10.2
react-v0.*
react-v0.10.2
v3.*
v3.16.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47705.json"