Логотип exploitDog
bind:CVE-2025-65098
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-65098

Количество 2

Количество 2

nvd логотип

CVE-2025-65098

17 дней назад

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript executes in their browser and exfiltrates their OpenAI keys, Google Sheets tokens, and SMTP passwords. The `/api/trpc/credentials.getCredentials` endpoint returns plaintext API keys without verifying credential ownership. Version 3.13.2 fixes the issue.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-4xc5-wfwc-jw47

17 дней назад

Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript executes in their browser and exfiltrates their OpenAI keys, Google Sheets tokens, and SMTP passwords. The `/api/trpc/credentials.getCredentials` endpoint returns plaintext API keys without verifying credential ownership. Version 3.13.2 fixes the issue.

CVSS3: 7.4
0%
Низкий
17 дней назад
github логотип
GHSA-4xc5-wfwc-jw47

Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass

CVSS3: 7.4
0%
Низкий
17 дней назад

Уязвимостей на страницу