TypeBot
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 27, 2021 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →TypeBot vulnerable to CSV injection in result export
TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server
TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots
TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access
TypeBot API tokens stored in plaintext
TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution
TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass
TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName
TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)
TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification
Monitor TypeBot in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.