CVE-2026-62862: TypeBot: Account takeover via brute-forceable 6-digit magic-link code
Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email provider overrides NextAuth's default cryptographically secure token with a 6-digit code generated using Math.random(), reducing the keyspace to 900,000 with a 10-minute expiry, and the code itself is the raw value placed in the magic link. The verification callback enforces no attempt limit, lockout, or CSRF protection, and an incorrect guess does not consume the real code because the adapter returns null on a not-found token, so a valid code survives unlimited guessing within its lifetime. The only rate limiter applies to the code-sending path and is keyed on the client-controlled X-Forwarded-For header, allowing an attacker to request many concurrent live codes for one victim and further raise the odds of a matching guess. As a result, an anonymous attacker who knows a victim's email address can brute-force the callback and obtain an authenticated session as that user with no victim interaction, gaining full access to the victim's bots, results, and connected integration credentials. Deployments configured for OAuth or SSO only, with no email provider, are not affected. This issue is fixed in version 3.18.0
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TypeBotto a version that resolves this vulnerability.Fixed in 3.18.0 - Compensating control
For deployments configured for OAuth or SSO only, with no email provider, note they are not affected; ensure the deployment uses OAuth/SSO without a passwordless email provider where applicable.
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Self-hosted Typebot deployments up to and including version 3.17.1 that use the default passwordless email magic-link authentication should be prioritized. The issue affects that default authentication flow.
What must an attacker know or control to exploit this?
An attacker only needs to know the victim's email address. No account privileges or victim interaction are required.
Do failed login-code guesses stop further attempts or invalidate the legitimate code?
No. The verification callback has no attempt limit or lockout, and an incorrect guess does not consume the valid code. The valid code remains guessable during its 10-minute lifetime.
How could an attacker increase the likelihood of a successful guess?
The code-sending rate limiter is keyed to the client-controlled X-Forwarded-For header. An attacker can use this to request many concurrent live codes for a victim, increasing the chance that a guessed code matches one of them.
What release is referenced for updating affected deployments?
The provided references include the Typebot v3.18.0 release and the associated remediation commit. Deployments on versions through 3.17.1 are described as affected.