CVE-2026-47705: TypeBot vulnerable to CSV injection in result export
TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TypeBotto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47705?
The severity of CVE-2026-47705 is rated as critical with a score of 9.6.
How do I fix CVE-2026-47705?
To fix CVE-2026-47705, update TypeBot to version 3.16.2 or later, which addresses the CSV injection vulnerability.
What type of vulnerability is CVE-2026-47705?
CVE-2026-47705 is a CSV injection vulnerability that occurs in the result export functionality of TypeBot.
What impact does CVE-2026-47705 have on users?
CVE-2026-47705 allows attackers to inject malicious spreadsheet formulas via input fields, potentially leading to execution of unauthorized commands.
Which version of TypeBot is affected by CVE-2026-47705?
TypeBot version 3.16.1 is affected by CVE-2026-47705.