TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication. Version 3.17.0 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baptistearno
Baptistearno typebot.io |
|
| Vendors & Products |
Baptistearno
Baptistearno typebot.io |
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication. Version 3.17.0 fixes the issue. | |
| Title | TypeBot API tokens stored in plaintext | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T14:46:52.969Z
Reserved: 2026-05-19T21:18:20.404Z
Link: CVE-2026-47702
Updated: 2026-08-11T14:46:48.388Z
Status : Received
Published: 2026-08-11T15:17:30.560
Modified: 2026-08-11T15:17:30.560
Link: CVE-2026-47702
No data.
OpenCVE Enrichment
Updated: 2026-08-11T23:30:06Z