CVE-2026-42142: TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the handleGetSheets API handler (POST /api/sheets/getSheets) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data (sheet names, IDs, column headers). Version 3.17.0 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
typebotto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42142?
CVE-2026-42142 has a severity rating of high, with a score of 7.1.
What does CVE-2026-42142 exploit?
CVE-2026-42142 exploits an authorization bypass in the TypeBot `getSheets` API endpoint.
How do I fix CVE-2026-42142?
To fix CVE-2026-42142, upgrade TypeBot to version 3.17.0 or later where the issue has been addressed.
What are the potential impacts of CVE-2026-42142?
The potential impact of CVE-2026-42142 includes unauthorized access to another workspace's Google Sheets OAuth credentials.
Who is affected by CVE-2026-42142?
Any authenticated user using TypeBot prior to version 3.17.0 may be affected by CVE-2026-42142.