Vulnerability  ·  2026-08-13

TypeBot chatbot builder — critical OAuth credential takeover via read-collaborator privilege escalation

VulnerabilityHigh impactGlobalCVE-2026-48765
NVD published CVE-2026-48765 (CVSS 9.9, Critical) describing a broken authorization check that lets a low-privilege collaborator escalate to full control of workspace OAuth credentials.
TypeBot is a widely-used open-source chatbot/conversational-AI builder; compromised OAuth credentials expose all downstream services (Google Sheets, OpenAI-compatible providers, etc.) connected to the workspace, enabling data theft or malicious bot reconfiguration.
A low-privilege read collaborator extracts a workspace OAuth credentialsId from a readable bot configuration, then overwrites that credential via handleUpdateOAuthCredentials() by supplying an attacker-controlled writable replacement, hijacking the workspace's connected OAuth integration.
TypeBot < 3.17.0
Upgrade to TypeBot >= 3.17.0.
NVD - CVE-2026-48765
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →