CVE-2025-64706: Typebot IDOR Vulnerability: Unauthorized API Token Deletion and Exposure
Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API token and retrieve its value by simply knowing the target user's ID and token ID, without requiring authorization checks. Version 3.13.0 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64706?
The severity of CVE-2025-64706 is considered high due to the potential for unauthorized API token deletion by authenticated attackers.
How do I fix CVE-2025-64706?
To fix CVE-2025-64706, upgrade Typebot to version 3.13.0 or later where the vulnerability has been addressed.
What impact does CVE-2025-64706 have on affected systems?
CVE-2025-64706 allows an authenticated attacker to delete or retrieve API tokens for any user, compromising their access and data.
Which versions of Typebot are affected by CVE-2025-64706?
Typebot versions from 3.9.0 up to but excluding 3.13.0 are affected by CVE-2025-64706.
Is CVE-2025-64706 an open-source vulnerability?
Yes, CVE-2025-64706 is a vulnerability found in the open-source chatbot builder Typebot.